PT-2022-16593 · Mongoose · Mongoose

Published

2022-08-27

·

Updated

2022-08-27

·

CVE-2022-24304

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mongoose (affected versions not specified)
Description The issue concerns a Prototype Pollution vulnerability in the Schema.path() function, allowing modification of the Object prototype. This could lead to a Denial of Service (DoS) attack. The vulnerability may also be exploited for other types of attacks, such as Remote Code Execution or Property Injection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24304
GHSA-H8HF-X3F4-XWGP

Affected Products

Mongoose