Junglewise Threat Intelligence

CVE-2019-2391: MongoDB js-bson deserialization of untrusted data

CVE-2019-2391 · Severity: low · CVSS 3.1 · Published 2022-02-10

Technologies: bson (npm). Vendors: MongoDB, npm.

Executive brief

The MongoDB js-bson library, which is used to serialize and deserialize BSON (binary JSON) data in Node.js and browser applications, contains a flaw in how it parses certain JSON input. An attacker could craft malicious JSON with an invalid _bsontype field that causes the library to serialize data incorrectly, potentially exposing sensitive information. Organizations using vulnerable versions should upgrade to version 1.1.4 or later.

Technical details

The vulnerability is a deserialization flaw (CWE-502) in MongoDB's js-bson library affecting versions prior to 1.1.4. The root cause is improper handling of invalid _bsontype fields during BSON serialization of JSON input. An attacker can supply specially crafted JSON with an unrecognized _bsontype value, bypassing expected type validation and causing incorrect serialization behavior. This can lead to data disclosure or unexpected application behavior. The attack requires an application that processes untrusted JSON input with the vulnerable bson library; the exact preconditions (authentication, network accessibility) depend on the application context. A patch was released in version 1.1.4 on March 24, 2020, which properly validates _bsontype fields during serialization.

Affected products

  • MongoDB js-bson <1.1.4

Timeline

  • 2020-03-31: disclosed: NVD publication date for CVE-2019-2391
  • 2020-03-24: patched: MongoDB released js-bson v1.1.4 with fix
  • 2022-02-10: advisory: GitHub Security Advisory GHSA-4jwp-vfvf-657p published

References

Related threats