CVE-2021-23372: Denial of Service (DoS)
Published Apr 13, 2021
·Updated
All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.
Affected Software
1 affected component
Mongo-express Project Mongo-express Node.js
Event History
Apr 13, 2021
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-23372.
2
What is the severity of CVE-2021-23372?
CVE-2021-23372 has a severity level of high.
3
Which versions of mongo-express are affected by CVE-2021-23372?
All versions of mongo-express are affected by CVE-2021-23372.
4
What is the impact of CVE-2021-23372?
CVE-2021-23372 can lead to a Denial of Service (DoS) attack by crashing the application when exporting an empty collection as CSV.
5
How can I fix CVE-2021-23372?
To fix CVE-2021-23372, update to a patched version or apply any available security patches for mongo-express.