CVE-2020-7610
30.03.2020, 19:15
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.Enginsight
Vendor | Product | Version |
---|---|---|
mongodb | bson | 1.0.0 ≤ 𝑥 < 1.1.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration