PT-2023-3708 · Mongoose · Mongoose

Vkarpov15

·

Publicado

2023-07-16

·

Atualizado

2024-03-06

·

CVE-2023-3696

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions mongoose versions prior to 7.3.4 mongoose versions prior to 6.11.3 mongoose versions prior to 5.13.20
Description The issue is related to a prototype pollution vulnerability in the Mongoose library. This vulnerability can be exploited by a remote attacker to perform a prototype pollution attack.
Recommendations For versions prior to 7.3.4, update to version 7.3.4 or later. For versions prior to 6.11.3, update to version 6.11.3 or later. For versions prior to 5.13.20, update to version 5.13.20 or later.

Exploit

Correção

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03996
BIT-MONGOOSE-2023-3696
CVE-2023-3696
GHSA-9M93-W8W6-76HH

Produtos afetados

Mongoose