Deserialization of Untrusted Data in bson
Critical severity
GitHub Reviewed
Published
May 7, 2021
to the GitHub Advisory Database
•
Updated Nov 28, 2023
Description
Published by the National Vulnerability Database
Mar 30, 2020
Reviewed
May 6, 2021
Published to the GitHub Advisory Database
May 7, 2021
Last updated
Nov 28, 2023
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsontype, leading to cases where an object is serialized as a document rather than the intended BSON type.
References