به Nostr بپیوندید
2025-02-21 23:44:09 CET

zCat on Nostr: Vulnerabilities in MongoDB Library Allow RCE on Node[.]js Servers Two ...

Vulnerabilities in MongoDB Library Allow RCE on Node[.]js Servers

Two critical-severity vulnerabilities in the Mongoose Object Data Modeling (ODM) library for MongoDB could have allowed attackers to achieve remote code execution (RCE) on Node[.]js application server.

The first of the critical-severity flaws in the library, tracked as CVE-2024-53900, could allow an attacker to exploit the $where value to potentially achieve RCE on Node.js. The second issue, tracked as CVE-2025-23061, is a bypass for CVE-2024-53900’s patch.

See more:
https://www.securityweek.com/vulnerabilities-in-mongodb-library-allow-rce-on-node-js-servers/

#security #nodejs #rce