{"id":"GHSA-9m93-w8w6-76hh","summary":"Mongoose Prototype Pollution vulnerability","details":"Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.3, 6.11.3, and 5.13.20.","aliases":["BIT-mongoose-2023-3696","CVE-2023-3696"],"modified":"2023-12-06T00:48:04.736853Z","published":"2023-07-17T03:30:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-18T16:57:08Z","nvd_published_at":"2023-07-17T01:15:08Z","cwe_ids":["CWE-1321"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3696"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/commit/e29578d2ec18a68aeb4717d66dd5eb66bae53de1"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/commit/f1efabf350522257364aa5c2cb36e441cf08f1a2"},{"type":"WEB","url":"https://github.com/automattic/mongoose/commit/305ce4ff789261df7e3f6e72363d0703e025f80d"},{"type":"PACKAGE","url":"https://github.com/Automattic/mongoose"},{"type":"WEB","url":"https://github.com/Automattic/mongoose/releases/tag/7.3.3"},{"type":"WEB","url":"https://huntr.dev/bounties/1eef5a72-f6ab-4f61-b31d-fc66f5b4b467"}],"affected":[{"package":{"name":"mongoose","ecosystem":"npm","purl":"pkg:npm/mongoose"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.0.0"},{"fixed":"7.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-9m93-w8w6-76hh/GHSA-9m93-w8w6-76hh.json"}},{"package":{"name":"mongoose","ecosystem":"npm","purl":"pkg:npm/mongoose"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.0.0"},{"fixed":"6.11.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-9m93-w8w6-76hh/GHSA-9m93-w8w6-76hh.json"}},{"package":{"name":"mongoose","ecosystem":"npm","purl":"pkg:npm/mongoose"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.13.20"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-9m93-w8w6-76hh/GHSA-9m93-w8w6-76hh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H"}]}