{"id":"GHSA-r5xw-q988-826m","aliases":[],"url":"https://o3.security/vulnerability/GHSA-r5xw-q988-826m","summary":"Remote Memory Exposure in mongoose","details":"Versions of `mongoose` before 4.3.6, 3.8.39 are vulnerable to remote memory exposure.\n\nTrying to save a number to a field of type Buffer on the affected mongoose versions allocates a chunk of uninitialized memory and stores it in the database.\n\n\n## Recommendation\n\nUpdate to version 4.3.6, 3.8.39 or later.","published":"2020-09-01T19:39:37Z","modified":"2023-12-07T22:05:28Z","cvss":{"score":5.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mongoose","fixedVersion":"3.8.39"},{"ecosystem":"npm","name":"mongoose","fixedVersion":"4.3.6"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Automattic/mongoose/issues/3764"},{"type":"WEB","url":"https://gist.github.com/ChALkeR/440bc3dfcbd9b6da75c3"},{"type":"WEB","url":"https://gist.github.com/ChALkeR/d4a8055625221b6e65f0"},{"type":"WEB","url":"https://www.npmjs.com/advisories/599"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-12-07T22:05:28Z"}}