{"id":"GHSA-rc4v-99cr-pjcm","aliases":[],"url":"https://o3.security/vulnerability/GHSA-rc4v-99cr-pjcm","summary":"Prototype Pollution in ali-security/mongoose","details":"### Impact\nThis vulnerability causes a Prototype Pollution in document.js, through functions such as findByIdAndUpdate().\nFor applications using Express and EJS, this can potentially allow remote code execution.\n\n### Patches\nThe original patched version for mongoose 5.3.3 did not include a fix for CVE-2023-3696. Therefore the existing version @seal-security/mongoose-fixed version 5.3.3 is affected by this vulnerability (though it is protected from CVE-2022-2564 and CVE-2019-17426). To mitigate this issue, a @seal-security/mongoose-fixed version 5.3.4 has been deployed. Note that this version is compatible with the original mongoose version 5.3.3, not version 5.3.4\n\n### References\nhttps://security.snyk.io/vuln/SNYK-JS-MONGOOSE-5777721\nhttps://github.com/advisories/GHSA-9m93-w8w6-76hh\nhttps://github.com/Automattic/mongoose/commit/f1efabf350522257364aa5c2cb36e441cf08f1a2\n","published":"2023-10-17T14:21:16Z","modified":"2023-10-17T14:21:16Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@seal-security/mongoose-fixed","fixedVersion":"5.3.4"}],"fix":{"url":"https://github.com/Automattic/mongoose/commit/f1efabf350522257364aa5c2cb36e441cf08f1a2","label":"Automattic/mongoose@f1efabf"},"references":[{"type":"WEB","url":"https://github.com/ali-security/mongoose/security/advisories/GHSA-rc4v-99cr-pjcm"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/commit/f1efabf350522257364aa5c2cb36e441cf08f1a2"},{"type":"PACKAGE","url":"https://github.com/ali-security/mongoose"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-MONGOOSE-5777721"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-10-17T14:21:16Z"}}