An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser.
Prevent prototype pollution in MongoDB database adapter.
Disable remote code execution through the MongoDB BSON parser.
Mikhail Shcherbakov (KTH), Cristian-Alexandru Staicu (CISPA) and Musard Balliu (KTH) working with Trend Micro Zero Day Initiative
{ "nvd_published_at": "2022-11-10T01:15:00Z", "cwe_ids": [ "CWE-1321" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2022-11-08T17:29:16Z" }