OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 02:48
发布时间
2020-09-04 03:39
GitHub 审查时间
2020-09-01 02:48
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-5mrr-rgp6-x4gr/GHSA-5mrr-rgp6-x4gr.json
All versions of marsdb are vulnerable to Command Injection. In the DocumentMatcher class, selectors on $where clauses are passed to a Function constructor unsanitized. This allows attackers to run arbitrary commands in the system when the function is executed.
No fix is currently available. Consider using an alternative package until a fix is made available.