Junglewise Threat Intelligence

CVE-2024-53900: Mongoose search injection vulnerability via $where operator

CVE-2024-53900 · Severity: low · CVSS 3.1 · Published 2024-12-02

Vendors: Automattic.

Executive brief

Mongoose, a popular MongoDB object modeling library for Node.js, contains a vulnerability in how it handles the $where operator in database queries. Attackers can inject arbitrary JavaScript code that gets executed in MongoDB queries, potentially allowing them to read, modify, or delete database contents. Applications using affected versions of Mongoose to process user-supplied search filters are at risk of code injection and unauthorized data access.

Technical details

This is a code injection vulnerability (CWE-89) arising from improper handling of the MongoDB $where operator in Mongoose query filters, particularly in the populate() method. The $where operator allows arbitrary JavaScript code execution within MongoDB queries. Versions prior to 3.6.0-rc0 are unaffected; the vulnerability was introduced in 3.6.0-rc0 and affects all subsequent versions until the respective patch releases. No authentication or user interaction is required—an attacker with network access to an application can supply malicious $where clauses through user input (search parameters, API payloads, etc.) to execute arbitrary JavaScript in the MongoDB context, compromising confidentiality, integrity, and availability of database data. Patches are available in versions 8.8.3, 7.8.3, 6.13.5, and 5.13.23.

Affected products

  • Automattic Mongoose Prior to 8.8.3, 7.8.3, 6.13.5, and 5.13.23

Timeline

  • 2024-12-02: disclosed
  • 2024-12-02: patched: Versions 8.8.3, 7.8.3, 6.13.5, and 5.13.23 released with fixes