Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0693 Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).
Github GHSA Github GHSA GHSA-8687-vv9j-hgph Improper Input Validation in Automattic Mongoose
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T01:40:15.456Z

Reserved: 2019-10-10T00:00:00

Link: CVE-2019-17426

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-10T02:05:46.833

Modified: 2024-11-21T04:32:18.333

Link: CVE-2019-17426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses