WeDoSoftware / status-check

0 stars 1 forks source link

A new vulnerability was discovered: CVE-2020-7610 #307

Open debricked[bot] opened 3 years ago

debricked[bot] commented 3 years ago

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

Read more at Debricked: https://app.debricked.com/en/service/vulnerability/154704