PT-2019-4513 · Mongodb · Mongo-Express

Jonathan Leitschuh

·

Publicado

2019-10-14

·

Atualizado

2025-03-13

·

CVE-2019-10758

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions mongo-express versions prior to 0.54.0
Description The issue is related to incorrect code generation management in the Mongo-express web interface for MongoDB database management. It allows a remote attacker to execute arbitrary code in the target system by sending a specially crafted request. The vulnerability is exploited via endpoints that use the toBSON method, which misuses the vm dependency to perform exec commands in a non-safe environment. This can lead to remote code execution on the host machine by any authenticated user.
Recommendations For versions prior to 0.54.0, upgrade to version 0.54.0 to resolve the issue. As a temporary workaround, consider restricting access to endpoints that use the toBSON method until the upgrade is applied. Avoid using the toBSON method in sensitive operations until the issue is resolved.

Exploit

Correção

RCE

OS Command Injection

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00407
CVE-2019-10758
GHSA-H47J-HC6X-H3QQ
SNYK-JS-MONGOEXPRESS-473215

Produtos afetados

Mongo-Express