PT-2019-4513 · Mongodb · Mongo-Express
Jonathan Leitschuh
·
Publicado
2019-10-14
·
Atualizado
2025-03-13
·
CVE-2019-10758
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
mongo-express versions prior to 0.54.0
Description
The issue is related to incorrect code generation management in the Mongo-express web interface for MongoDB database management. It allows a remote attacker to execute arbitrary code in the target system by sending a specially crafted request. The vulnerability is exploited via endpoints that use the
toBSON method, which misuses the vm dependency to perform exec commands in a non-safe environment. This can lead to remote code execution on the host machine by any authenticated user.Recommendations
For versions prior to 0.54.0, upgrade to version 0.54.0 to resolve the issue. As a temporary workaround, consider restricting access to endpoints that use the
toBSON method until the upgrade is applied. Avoid using the toBSON method in sensitive operations until the issue is resolved.Exploit
Correção
RCE
OS Command Injection
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mongo-Express