
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (CVE-2019-2391) affects MongoDB Inc.'s js-bson library version 1.1.3 and prior versions. The issue involves incorrect parsing of certain JSON input that may result in js-bson not correctly serializing BSON, potentially leading to unexpected application behavior including data disclosure (NVD, CVE Mitre).
The vulnerability stems from an issue with BSON serialization when handling invalid _bsontype values. The issue was originally reported by user @xiaofen9 and was subsequently addressed in version 1.1.4 of the bson module (GitHub Release).
The vulnerability can result in unexpected application behavior and potential data disclosure when processing certain JSON inputs (NVD).
The vulnerability has been fixed in js-bson version 1.1.4. MongoDB recommends that all users pin their version of the bson module to 1.1.4 or higher to address this security issue (GitHub Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."