Deserialization of Untrusted Data in bson
Moderate severity
GitHub Reviewed
Published
Feb 10, 2022
to the GitHub Advisory Database
•
Updated Jun 20, 2023
Description
Published by the National Vulnerability Database
Mar 31, 2020
Reviewed
May 7, 2021
Published to the GitHub Advisory Database
Feb 10, 2022
Last updated
Jun 20, 2023
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure.
References