First published: Wed Jan 15 2025(Updated: )
Mongoose before 8.9.5 can improperly use a $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
Credit: cve@mitre.org
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.