PT-2022-17426 · Mongoose · Mongoose

Vkarpov15

·

Published

2022-07-28

·

Updated

2024-03-12

·

CVE-2022-2564

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions mongoose versions prior to 6.4.6
Description The issue concerns a Prototype Pollution vulnerability in the mongoose package, a MongoDB object modeling tool. This vulnerability affects the Schema.path() function, allowing modification of the Object prototype, which could potentially lead to a Denial of Service (DoS) attack.
Recommendations For versions prior to 6.4.6, update to version 6.4.6 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Schema.path() function until a patch is applied.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

BIT-MONGOOSE-2022-2564
CVE-2022-2564
GHSA-F825-F98C-GJ3G

Affected Products

Mongoose