CVE-2024-53900

Updated on 02 Dec 2024

Severity

9.1 Critical severity

Details

CVSS score
9.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Overview

About vulnerability

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

Details

Affected product:
mongoose
Affected packages:
mongoose @ 6.12.2 (+1 more)
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

Fixes