querymen@2.0.0 vulnerabilities
Querystring parser middleware for MongoDB, Express and Nodejs
-
latest version
2.1.4
-
first published
9 years ago
-
latest version published
5 years ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the querymen package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
querymen is a Querystring parser middleware for MongoDB, Express and Nodejs. Affected versions of this package are vulnerable to Prototype Pollution if the parameters of exported function Note: This vulnerability derives from an incomplete fix of CVE-2020-7600. How to fix Prototype Pollution? There is no fixed version for |
*
|
querymen is a Querystring parser middleware for MongoDB, Express and Nodejs. Affected versions of this package are vulnerable to Prototype Pollution. The parameters of exported function PoC by System Security Lab
How to fix Prototype Pollution? Upgrade |
<2.1.4
|