An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.
Prevent prototype pollution in MongoDB database adapter.
Disable remote code execution through the MongoDB BSON parser.
Mikhail Shcherbakov (KTH), Cristian-Alexandru Staicu (CISPA) and Musard Balliu (KTH) working with Trend Micro Zero Day Initiative
{
"severity": "CRITICAL",
"cwe_ids": [
"CWE-1321"
],
"nvd_published_at": "2022-11-10T01:15:00Z",
"github_reviewed_at": "2022-11-08T17:29:16Z",
"github_reviewed": true
}