mongoose is vulnerable to NoSQL Injection
95
Critical Risk
Affected versions of this package are vulnerable to NoSQL injection in the getModelsMapForPopulate function. This vulnerability allows attackers to exploit the $where clause within the match options, enabling them to execute arbitrary JavaScript code or manipulate database queries. This can lead to unauthorized data access, data manipulation, or potential denial of service, depending on the application's setup and the database permissions.
You are affected if you are using a version which is within vulnerability ranges
mongoose is vulnerable to NoSQL Injection in versions 5.6.4 - 8.8.2.
Upgrade the mongoose library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant