MEDIUM 5.1 npm

Remote Memory Exposure in mongoose

GHSA-r5xw-q988-826m

Published · Modified

Description

Versions of mongoose before 4.3.6, 3.8.39 are vulnerable to remote memory exposure.

Trying to save a number to a field of type Buffer on the affected mongoose versions allocates a chunk of uninitialized memory and stores it in the database.

Recommendation

Update to version 4.3.6, 3.8.39 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes