CVE-2019-2391
published 2020-03-31CVE-2019-2391: Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data…
PriorityP425medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.91%
56.4th percentile
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-mongodb | < node-mongodb 3.5.6+~cs11.12.19-1 (bookworm) | node-mongodb 3.5.6+~cs11.12.19-1 (bookworm) |
| mongodb | bson | >= 0 < 1.1.4 | 1.1.4 |
| mongodb | js-bson | < 1.1.4 | 1.1.4 |
| mongodb_inc | js-bson | 1.0 – 1.1.3 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv5.4MEDIUM
vendor_debian4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Deserialization of Untrusted Data in bson
osv·2022-02-10
CVE-2019-2391 [MEDIUM] Deserialization of Untrusted Data in bson
Deserialization of Untrusted Data in bson
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure.
GHSA
Deserialization of Untrusted Data in bson
ghsa·2022-02-10
CVE-2019-2391 [MEDIUM] CWE-502 Deserialization of Untrusted Data in bson
Deserialization of Untrusted Data in bson
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure.
OSV
CVE-2019-2391: Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON
osv·2020-03-31·CVSS 5.4
CVE-2019-2391 [MEDIUM] CVE-2019-2391: Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.
Debian
CVE-2019-2391: node-mongodb - Incorrect parsing of certain JSON input may result in js-bson not correctly seri...
vendor_debian·2019·CVSS 4.2
CVE-2019-2391 [MEDIUM] CVE-2019-2391: node-mongodb - Incorrect parsing of certain JSON input may result in js-bson not correctly seri...
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.
Scope: local
bookworm: resolved (fixed in 3.5.6+~cs11.12.19-1)
bullseye: resolved (fixed in 3.5.6+~cs11.12.19-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-03-31
Published