QID 981965
QID 981965: Nodejs (npm) Security Update for mongoose (GHSA-8687-vv9j-hgph)
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8687-vv9j-hgph for updates pertaining to this vulnerability.
Vendor References
- GHSA-8687-vv9j-hgph -
github.com/advisories/GHSA-8687-vv9j-hgph
CVEs related to QID 981965
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8687-vv9j-hgph | mongoose |
|