PT-2023-3708 · Mongoose · Mongoose

Vkarpov15

·

Published

2023-07-16

·

Updated

2024-03-06

·

CVE-2023-3696

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions mongoose versions prior to 7.3.4 mongoose versions prior to 6.11.3 mongoose versions prior to 5.13.20
Description The issue is related to a prototype pollution vulnerability in the Mongoose library. This vulnerability can be exploited by a remote attacker to perform a prototype pollution attack.
Recommendations For versions prior to 7.3.4, update to version 7.3.4 or later. For versions prior to 6.11.3, update to version 6.11.3 or later. For versions prior to 5.13.20, update to version 5.13.20 or later.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03996
BIT-MONGOOSE-2023-3696
CVE-2023-3696
GHSA-9M93-W8W6-76HH

Affected Products

Mongoose