CVE-2020-7610

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
30/03/2020
Last modified:
01/04/2020

Description

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mongodb:bson:*:*:*:*:*:node.js:*:* 1.0.0 (including) 1.1.4 (excluding)


References to Advisories, Solutions, and Tools