Vulnerabilities/

Command Injection in marsdb

Severity:
High

Description

All versions of marsdb are vulnerable to Command Injection. In the DocumentMatcher class, selectors on $where clauses are passed to a Function constructor unsanitized. This allows attackers to run arbitrary commands in the system when the function is executed.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
marsdb
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing