Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request for backport fix of CVE-2024-53900 vulnerability to Mongoose v6.x #15078

Open
2 tasks done
mlevy-parasoft opened this issue Dec 5, 2024 · 3 comments
Open
2 tasks done
Milestone

Comments

@mlevy-parasoft
Copy link

Prerequisites

  • I have written a descriptive issue title
  • I have searched existing issues to ensure the bug has not already been reported

Mongoose version

6.x

Node.js version

14.x

MongoDB server version

4.x

Typescript version (if applicable)

No response

Description

This is a request for backporting the fix here to 6.x:
c9e86bf

Steps to Reproduce

N/A

Expected Behavior

No response

@AlvaroVega
Copy link

And maybe for mongoose v5.x which is also still very used: https://www.npmjs.com/package/mongoose/v/5.13.22?activeTab=versions

@mlevy-parasoft
Copy link
Author

It looks like this fix was already backported for 6.x, but it is still showing up as vulnerable because the NVD hasn't been updated yet. I see there were attempts to remedy this in the following issues:
#15074
github/advisory-database#5053

I am not sure when the NVD will reflect these updates, but I am closing this issue since the fix is already backported.

@vkarpov15
Copy link
Collaborator

We will consider backporting this to 5.x. 5.x has been EOL since March 1 2024, but I think we can make an exception.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants