CVE-2019-2391: JS-bson may incorrectly serialise some requests
Published Mar 31, 2020
·Updated
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.
Affected Software
1 affected component
MongoDB JS-bson<1.1.4
Remediation
Patch Available
Event History
Mar 31, 2020
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-2391.
2
What is the severity of CVE-2019-2391?
The severity of CVE-2019-2391 is medium with a CVSS score of 5.4.
3
Which software is affected by CVE-2019-2391?
The MongoDB Inc. js-bson library version 1.1.3 and prior to 1.1.4 is affected.
4
What is the impact of CVE-2019-2391?
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON, leading to unexpected application behavior including data disclosure.
5
How do I fix CVE-2019-2391?
To fix CVE-2019-2391, update the js-bson library to version 1.1.4 or newer.