Описание
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.
Ссылки
- PatchRelease NotesThird Party Advisory
- PatchRelease NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.4 (исключая)
cpe:2.3:a:mongodb:js-bson:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00379
Низкий
4.2 Medium
CVSS3
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-502
CWE-502
Связанные уязвимости
CVSS3: 4.2
ubuntu
почти 6 лет назад
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.
CVSS3: 4.2
debian
почти 6 лет назад
Incorrect parsing of certain JSON input may result in js-bson not corr ...
EPSS
Процентиль: 59%
0.00379
Низкий
4.2 Medium
CVSS3
5.4 Medium
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-502
CWE-502