Remote Memory Exposure in mongoose
Moderate severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Dec 7, 2023
Package
Affected versions
>= 3.5.5, <= 3.8.38
>= 4.0.0, <= 4.3.5
Patched versions
3.8.39
4.3.6
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Dec 7, 2023
Versions of
mongoose
before 4.3.6, 3.8.39 are vulnerable to remote memory exposure.Trying to save a number to a field of type Buffer on the affected mongoose versions allocates a chunk of uninitialized memory and stores it in the database.
Recommendation
Update to version 4.3.6, 3.8.39 or later.
References