{"id":"GHSA-rc4v-99cr-pjcm","summary":"Prototype Pollution in ali-security/mongoose","details":"### Impact\nThis vulnerability causes a Prototype Pollution in document.js, through functions such as findByIdAndUpdate().\nFor applications using Express and EJS, this can potentially allow remote code execution.\n\n### Patches\nThe original patched version for mongoose 5.3.3 did not include a fix for CVE-2023-3696. Therefore the existing version @seal-security/mongoose-fixed version 5.3.3 is affected by this vulnerability (though it is protected from CVE-2022-2564 and CVE-2019-17426). To mitigate this issue, a @seal-security/mongoose-fixed version 5.3.4 has been deployed. Note that this version is compatible with the original mongoose version 5.3.3, not version 5.3.4\n\n### References\nhttps://security.snyk.io/vuln/SNYK-JS-MONGOOSE-5777721\nhttps://github.com/advisories/GHSA-9m93-w8w6-76hh\nhttps://github.com/Automattic/mongoose/commit/f1efabf350522257364aa5c2cb36e441cf08f1a2\n","modified":"2023-10-17T14:21:16Z","published":"2023-10-17T14:21:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-10-17T14:21:16Z","nvd_published_at":null,"cwe_ids":["CWE-1321"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/ali-security/mongoose/security/advisories/GHSA-rc4v-99cr-pjcm"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/commit/f1efabf350522257364aa5c2cb36e441cf08f1a2"},{"type":"PACKAGE","url":"https://github.com/ali-security/mongoose"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-MONGOOSE-5777721"}],"affected":[{"package":{"name":"@seal-security/mongoose-fixed","ecosystem":"npm","purl":"pkg:npm/%40seal-security/mongoose-fixed"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.3.3"},{"fixed":"5.3.4"}]}],"versions":["5.3.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-rc4v-99cr-pjcm/GHSA-rc4v-99cr-pjcm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H"}]}