CVE-2020-7610
published 2020-03-30CVE-2020-7610: All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.16%
80.2th percentile
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-mongodb | < node-mongodb 3.5.6+~cs11.12.19-1 (bookworm) | node-mongodb 3.5.6+~cs11.12.19-1 (bookworm) |
| mongodb | bson | — | — |
| mongodb | bson | >= 0 < 1.1.4 | 1.1.4 |
| mongodb | bson | >= 1.0.0 < 1.1.4 | 1.1.4 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Deserialization of Untrusted Data in bson
osv·2021-05-07
CVE-2020-7610 [CRITICAL] Deserialization of Untrusted Data in bson
Deserialization of Untrusted Data in bson
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsontype, leading to cases where an object is serialized as a document rather than the intended BSON type.
GHSA
Deserialization of Untrusted Data in bson
ghsa·2021-05-07
CVE-2020-7610 [CRITICAL] CWE-502 Deserialization of Untrusted Data in bson
Deserialization of Untrusted Data in bson
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsontype, leading to cases where an object is serialized as a document rather than the intended BSON type.
OSV
CVE-2020-7610: All versions of bson before 1
osv·2020-03-30·CVSS 9.8
CVE-2020-7610 [CRITICAL] CVE-2020-7610: All versions of bson before 1
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.
Red Hat
bson: Deserialization of Untrusted Data could result in Code injection or Excessive CPU load
vendor_redhat·2020-03-24·CVSS 9.8
CVE-2020-7610 [CRITICAL] CWE-502 bson: Deserialization of Untrusted Data could result in Code injection or Excessive CPU load
bson: Deserialization of Untrusted Data could result in Code injection or Excessive CPU load
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.
Package: bson (Red Hat OpenShift Application Runtimes) - Not affected
Debian
CVE-2020-7610: node-mongodb - All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted...
vendor_debian·2020·CVSS 9.8
CVE-2020-7610 [CRITICAL] CVE-2020-7610: node-mongodb - All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted...
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.
Scope: local
bookworm: resolved (fixed in 3.5.6+~cs11.12.19-1)
bullseye: resolved (fixed in 3.5.6+~cs11.12.19-1)
No detection rules found.
No public exploits indexed.
2020-03-30
Published