CVE-2020-24391: Input Validation
Published Mar 30, 2021
·Updated
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.
Affected Software
2 affected componentsFixes available
npm/mongodb-query-parser<2.0.0
2.0.0
Mongo-express Project Mongo-express Node.js<=0.54.0
Remediation
Event History
Mar 30, 2021
CVE Published
via MITRE·08:52 PM
Data Sourced
via MITRE·08:52 PM
Description
Apr 13, 2021
Advisory Published
03:41 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-24391?
The severity of CVE-2020-24391 is critical with a CVSS score of 9.8.
2
How does CVE-2020-24391 affect mongo-express?
CVE-2020-24391 affects mongo-express versions up to and including 0.54.0.
3
What is the remedy for CVE-2020-24391 in mongo-express?
The remedy for CVE-2020-24391 in mongo-express is to update to version 2.0.0 or later.
4
What is the affected package for CVE-2020-24391?
The affected package for CVE-2020-24391 is `mongodb-query-parser`.
5
Are there any known references for CVE-2020-24391?
Yes, you can find references for CVE-2020-24391 on the NIST National Vulnerability Database (NVD), GitHub issues, and GitHub commits.