Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v8w9-2789-6hhr

Опубликовано: 07 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Deserialization of Untrusted Data in bson

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsontype, leading to cases where an object is serialized as a document rather than the intended BSON type.

Пакеты

Наименование

bson

npm
Затронутые версииВерсия исправления

< 1.1.4

1.1.4

EPSS

Процентиль: 67%
0.00541
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 6 лет назад

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

CVSS3: 9.8
redhat
почти 6 лет назад

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

CVSS3: 9.8
nvd
почти 6 лет назад

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

CVSS3: 9.8
debian
почти 6 лет назад

All versions of bson before 1.1.4 are vulnerable to Deserialization of ...

CVSS3: 9.8
fstec
почти 6 лет назад

Уязвимость функции _bsotype программного пакета для парсинга BSON, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 67%
0.00541
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502