Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
| Software | From | Fixed in |
|---|---|---|
| mongoosejs / mongoose | - | 6.13.5 |
| mongoosejs / mongoose | 7.0.1 | 7.8.3 |
| mongoosejs / mongoose | 8.0.1 | 8.8.3 |
| mongoosejs / mongoose | 7.0.0-rc0 | 7.0.0-rc0.x |
| mongoosejs / mongoose | 8.0.0-rc0 | 8.0.0-rc0.x |