Information Exposure Affecting mongoose package, versions <4.13.21 >=5.0.0 <5.7.5
Threat Intelligence
EPSS
0.19% (58th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-MONGOOSE-472486
- published 10 Oct 2019
- disclosed 10 Jul 2019
- credit xiaofen9
Introduced: 10 Jul 2019
CVE-2019-17426 Open this link in a new tabHow to fix?
Upgrade mongoose
to version 4.13.21, 5.7.5 or higher.
Overview
mongoose is a Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.
Affected versions of this package are vulnerable to Information Exposure. Any query object with a _bsontype
attribute is ignored, allowing attackers to bypass access control.
References
CVSS Scores
version 3.1