Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4jwp-vfvf-657p

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Deserialization of Untrusted Data in bson

Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure.

Пакеты

Наименование

bson

npm
Затронутые версииВерсия исправления

< 1.1.4

1.1.4

EPSS

Процентиль: 59%
0.00379
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 4.2
ubuntu
почти 6 лет назад

Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.

CVSS3: 4.2
nvd
почти 6 лет назад

Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.

CVSS3: 4.2
debian
почти 6 лет назад

Incorrect parsing of certain JSON input may result in js-bson not corr ...

EPSS

Процентиль: 59%
0.00379
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-502