CVE-2020-7610
30.03.2020, 19:15
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mongodb | bson | 1.0.0 ≤ 𝑥 < 1.1.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration