Executive brief
The bson JavaScript library, used to parse and serialize binary data in MongoDB applications, fails to validate the _bsontype field during deserialization. An attacker can supply a malicious bson object with an invalid _bsontype value, causing it to be serialized as a generic document instead of the intended type, potentially leading to type confusion attacks that bypass application logic or expose sensitive data.
Technical details
This is a deserialization vulnerability (CWE-502) in the bson npm package affecting all versions before 1.1.4. The vulnerability arises because the serializer ignores unknown or invalid values for the _bsontype property during object serialization, allowing an attacker to construct a malicious object that will be serialized as an unintended BSON type. The attack requires no authentication or user interaction and is remotely exploitable over the network. An attacker can craft a payload with an invalid _bsontype to cause type confusion, potentially bypassing security checks or enabling object injection attacks. The vulnerability was patched in version 1.1.4 to throw an error when an invalid _bsontype is detected during serialization.
Affected products
- MongoDB bson before 1.1.4
Timeline
- 2021-05-07: disclosed: GHSA-v8w9-2789-6hhr published
- 2020-03-30: patched: CVE-2020-7610 reported; fix committed to js-bson