Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vg7j-7cwx-8wgw | Mongoose search injection vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 03 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:* |
Wed, 15 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Jan 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mongoose before 8.9.5 can improperly use a $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900. | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900. |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Wed, 15 Jan 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mongoose before 8.9.5 can improperly use a $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-15T15:11:21.314Z
Reserved: 2025-01-10T00:00:00
Link: CVE-2025-23061
Updated: 2025-01-15T15:07:04.256Z
Status : Analyzed
Published: 2025-01-15T05:15:10.517
Modified: 2025-10-03T12:59:11.117
Link: CVE-2025-23061
No data.
OpenCVE Enrichment
Updated: 2025-06-16T20:37:57Z
Github GHSA