Security Advisory

CVE-2020-7610

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-03-30 18:28:17
Last updated 2024-08-04 09:33:19
Assigner snyk
CVSS score not scored
State PUBLISHED

Description

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.