CVE-2024-53900
02.12.2024, 20:15
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
Vendor | Product | Version |
---|---|---|
mongoosejs | mongoose | 𝑥 < 6.13.5 |
mongoosejs | mongoose | 7.0.1 ≤ 𝑥 < 7.8.3 |
mongoosejs | mongoose | 8.0.1 ≤ 𝑥 < 8.8.3 |
mongoosejs | mongoose | 7.0.0:rc0 |
mongoosejs | mongoose | 8.0.0:rc0 |
𝑥
= Vulnerable software versions
References