First published: Tue Apr 13 2021(Updated: )
All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-23372.
CVE-2021-23372 has a severity level of high.
All versions of mongo-express are affected by CVE-2021-23372.
CVE-2021-23372 can lead to a Denial of Service (DoS) attack by crashing the application when exporting an empty collection as CSV.
To fix CVE-2021-23372, update to a patched version or apply any available security patches for mongo-express.