CVE-2024-53900

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
02/12/2024
Last modified:
01/10/2025

Description

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:* 6.13.5 (excluding)
cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:* 7.0.1 (including) 7.8.3 (excluding)
cpe:2.3:a:mongoosejs:mongoose:*:*:*:*:*:node.js:*:* 8.0.1 (including) 8.8.3 (excluding)
cpe:2.3:a:mongoosejs:mongoose:7.0.0:rc0:*:*:*:node.js:*:*
cpe:2.3:a:mongoosejs:mongoose:8.0.0:rc0:*:*:*:node.js:*:*