Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

chore(deps): [security] bump mongoose from 4.2.4 to 5.9.22 #84

Closed

Conversation

dependabot-preview[bot]
Copy link

Bumps mongoose from 4.2.4 to 5.9.22. This update includes security fixes.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

Moderate severity vulnerability that affects mongoose Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).

Affected versions: < 5.7.5

Sourced from The Node Security Working Group.

Remote Memory Exposure Trying to save a number to a field of type Buffer on the affected mongoose versions allocates a chunk of uninitialized memory and stores it in the database.

Affected versions: >=3.5.5 =4.0.0 <=4.3.5

Changelog

Sourced from mongoose's changelog.

5.9.22 / 2020-07-06

  • fix(schema): treat { type: mongoose.Schema.Types.Array } as equivalent to { type: Array } #9194
  • fix: revert fix for #9107 to avoid issues when calling connect() multiple times #9167
  • fix(update): respect storeSubdocValidationError option with update validators #9172
  • fix: upgrade to safe-buffer 5.2 #9198
  • docs: add a note about SSL validation to migration guide #9147
  • docs(schemas): fix inconsistent header #9196 samtsai15

5.9.21 / 2020-07-01

  • fix: propagate typeKey option to implicitly created schemas from typePojoToMixed #9185 joaoritter
  • fix(populate): handle embedded discriminator refPath with multiple documents #9153
  • fix(populate): handle deselected foreign field with perDocumentLimit and multiple documents #9175
  • fix(document): disallow transform functions that return promises #9176 #9163 AbdelrahmanHafez
  • fix(document): use strict equality when checking mixed paths for modifications #9165
  • docs: add target="_blank" to all edit links #9058

5.9.20 / 2020-06-22

  • fix(populate): handle populating primitive array under document array discriminator #9148
  • fix(connection): make sure to close previous connection when calling openUri() on an already open connection #9107
  • fix(model): fix conflicting $setOnInsert default values with update values in bulkWrite #9160 #9157 AbdelrahmanHafez
  • docs(validation): add note about validateBeforeSave and invalidate #9144 dandv
  • docs: specify the array field syntax for invalidate #9137 dandv
  • docs: fix several typos and broken references #9024 AbdelrahmanHafez
  • docs: fix minor typo #9143 dandv

5.9.19 / 2020-06-15

  • fix: upgrade mongodb driver -> 3.5.9 #9124 AbdelrahmanHafez
  • fix: copy required validator on single nested subdoc correctly when calling Schema#clone() #8819
  • fix(discriminator): handle tiedValue when casting update on nested paths #9108
  • fix(model): allow empty arrays for bulkWrite #9132 #9131 AbdelrahmanHafez
  • fix(schema): correctly set partialFilterExpression for nested schema indexes #9091
  • fix(castArrayFilters): handle casting on all fields of array filter #9122 lafeuil
  • fix(update): handle nested path createdAt when overwriting parent path #9105
  • docs(subdocs): add some notes on the difference between single nested subdocs and nested paths #9085
  • docs(subdocs): improve docs on typePojoToMixed #9085
  • docs: add note about connections in globalSetup with Jest #9063
  • docs: add schema and how to set default sub-schema to schematype options #9111 dfle
  • docs(index): use const instead of var in examples #9125 dmcgrouther
  • docs: corrected markdown typo #9117

5.9.18 / 2020-06-05

  • fix: improve atlas error in the event of incorrect password #9095
  • docs: add edit link for all docs pages #9058
  • fix(document): allow accessing $locals when initializing document #9099 #9098 AbdelrahmanHafez
  • fix(query): make setDefaultsOnInsert a mongoose option so it doesn't end up in debug output #9086
Commits
  • fa246e7 chore: release 5.9.22
  • a3f61ad refactor: upgrade to safe-buffer 5.2, remove workaround for #7102
  • 09b59e4 fix: revert fix for #9107 to avoid issues when calling connect() multiple t...
  • 3390c53 fix(schema): treat { type: mongoose.Schema.Types.Array } as equivalent to `...
  • 378f59b test(schema): repro #9194
  • 8ea7743 Merge pull request #9196 from samtsai15/patch-1
  • 6fea8c3 docs: add a note about SSL validation to migration guide
  • 86e2791 fix(update): respect storeSubdocValidationError option with update validators
  • f3be507 test(update): repro #9172
  • fd42b58 Update guide.pug
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [mongoose](https://github.com/Automattic/mongoose) from 4.2.4 to 5.9.22. **This update includes security fixes.**
- [Release notes](https://github.com/Automattic/mongoose/releases)
- [Changelog](https://github.com/Automattic/mongoose/blob/master/History.md)
- [Commits](Automattic/mongoose@4.2.4...5.9.22)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Jul 7, 2020
@dependabot-preview
Copy link
Author

Superseded by #85.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants