Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8687-vv9j-hgph

Опубликовано: 22 окт. 2019
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Improper Input Validation in Automattic Mongoose

Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).

Пакеты

Наименование

mongoose

npm
Затронутые версииВерсия исправления

>= 5.0.0, < 5.7.5

5.7.5

Наименование

mongoose

npm
Затронутые версииВерсия исправления

< 4.13.21

4.13.21

EPSS

Процентиль: 47%
0.00237
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.1
nvd
больше 6 лет назад

Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).

EPSS

Процентиль: 47%
0.00237
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-20