zCat on Nostr: Vulnerabilities in MongoDB Library Allow RCE on Node[.]js Servers Two ...
Vulnerabilities in MongoDB Library Allow RCE on Node[.]js Servers
Two critical-severity vulnerabilities in the Mongoose Object Data Modeling (ODM) library for MongoDB could have allowed attackers to achieve remote code execution (RCE) on Node[.]js application server.
The first of the critical-severity flaws in the library, tracked as CVE-2024-53900, could allow an attacker to exploit the $where value to potentially achieve RCE on Node.js. The second issue, tracked as CVE-2025-23061, is a bypass for CVE-2024-53900’s patch.
See more:
https://www.securityweek.com/vulnerabilities-in-mongodb-library-allow-rce-on-node-js-servers/#security #nodejs #rce
Published at
2025-02-21 23:44:09 CETEvent JSON
{
"id": "f7a6f041821a0dd560bb22552cca0fea81e576e037e79e4d170c1e23963de10d",
"pubkey": "16fd26f00054f66151c6bd7925edef41586103af19d445f93f66f5e24b34427a",
"created_at": 1740177849,
"kind": 1,
"tags": [
[
"t",
"security"
],
[
"t",
"nodejs"
],
[
"t",
"rce"
],
[
"r",
"Node.js."
],
[
"r",
"https://www.securityweek.com/vulnerabilities-in-mongodb-library-allow-rce-on-node-js-servers/"
]
],
"content": "Vulnerabilities in MongoDB Library Allow RCE on Node[.]js Servers\n\nTwo critical-severity vulnerabilities in the Mongoose Object Data Modeling (ODM) library for MongoDB could have allowed attackers to achieve remote code execution (RCE) on Node[.]js application server.\n\nThe first of the critical-severity flaws in the library, tracked as CVE-2024-53900, could allow an attacker to exploit the $where value to potentially achieve RCE on Node.js. The second issue, tracked as CVE-2025-23061, is a bypass for CVE-2024-53900’s patch.\n\nSee more:\nhttps://www.securityweek.com/vulnerabilities-in-mongodb-library-allow-rce-on-node-js-servers/\n\n#security #nodejs #rce",
"sig": "216bcd1210faaba8487386677a923e9385f06695b7849560004d96d13f3cd471867446ddd4f5c5d7bb6e34026ad246dfd871e745da0d583e33e6e5fc901a4c78"
}