GHSA-hxwc-5vw9-2w4w

Suggest an improvement
Source
https://github.com/advisories/GHSA-hxwc-5vw9-2w4w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hxwc-5vw9-2w4w/GHSA-hxwc-5vw9-2w4w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hxwc-5vw9-2w4w
Published
2020-09-02T15:52:39Z
Modified
2021-09-27T15:13:26Z
Summary
NoSQL Injection in loopback-connector-mongodb
Details

Versions of loopback-connector-mongodb prior to 3.6.0 are vulnerable to NoSQL Injection. Filters passed to the database query are not properly sanitized which leads to execution of code on the database driver and data leak.

Recommendation

Upgrade to version 3.6.0 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-89"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:35:00Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / loopback-connector-mongodb

Package

Name
loopback-connector-mongodb
View open source insights on deps.dev
Purl
pkg:npm/loopback-connector-mongodb

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.6.0

Database specific

last_known_affected_version_range
"<= 3.5.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hxwc-5vw9-2w4w/GHSA-hxwc-5vw9-2w4w.json"