QID 983474
QID 983474: Nodejs (npm) Security Update for mongo-express (GHSA-h47j-hc6x-h3qq)
Security update has been released for mongo-express to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Remote code execution on the host machine by any authenticated user.
Solution
Users should upgrade to version `0.54.0`Workaround:
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
Vendor References
- GHSA-h47j-hc6x-h3qq -
github.com/advisories/GHSA-h47j-hc6x-h3qq
CVEs related to QID 983474
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h47j-hc6x-h3qq | mongo-express |
|