Mongoose 是一个用于异步环境的 MongoDB 对象建模工具。在版本 6.13.10、7.8.10、8.24.1 和 9.7.2 之前,若通过传递用户可控的更新操作(例如 ),攻击者可以利用 Mongoose 的更新类型转换机制,在 操作中使用形如 的点分路径进行注入。这种不当处理可能导致 和 将继承自 和 的内置属性误识别为 schema 类型,从而在抛出异常前,将 和 等属性设置到 上。该原型污染漏洞会使这些属性在后续创建的新对象中可见,进而可能导致应用程序完整性与可用性问题。该问题已在版本 6.13.
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Automattic | mongoose | < 6.13.10 |
affected |
>= 7.0.0, < 7.8.10 |
affected | ||
>= 8.0.0, < 8.24.1 |
affected | ||
>= 9.0.0, < 9.7.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Automattic | mongoose | < 6.13.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet