All vulnerabilities
CVE-2022-2564
automattic/mongoose vulnerable to Prototype pollution via Schema.path
Description
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Affected versions of this package are vulnerable to Prototype Pollution. The Schema.path() function is vulnerable to prototype pollution when setting the schema object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.
Patch Available
Fix available through Seal Security.
No upgrade required, protect your application instantly.
Fix without upgrading
Score
Severity
Ecosystem
JavaScript
Publish Date
July 28, 2022
Modified Date
December 5, 2023
Score Vector
Affected Versions

