Junglewise Threat Intelligence

CVE-2020-7610: MongoDB bson deserialization of untrusted data

CVE-2020-7610 · Severity: low · CVSS 3.1 · Published 2021-05-07

Technologies: bson (npm). Vendors: npm, MongoDB.

Executive brief

The bson JavaScript library, used to parse and serialize binary data in MongoDB applications, fails to validate the _bsontype field during deserialization. An attacker can supply a malicious bson object with an invalid _bsontype value, causing it to be serialized as a generic document instead of the intended type, potentially leading to type confusion attacks that bypass application logic or expose sensitive data.

Technical details

This is a deserialization vulnerability (CWE-502) in the bson npm package affecting all versions before 1.1.4. The vulnerability arises because the serializer ignores unknown or invalid values for the _bsontype property during object serialization, allowing an attacker to construct a malicious object that will be serialized as an unintended BSON type. The attack requires no authentication or user interaction and is remotely exploitable over the network. An attacker can craft a payload with an invalid _bsontype to cause type confusion, potentially bypassing security checks or enabling object injection attacks. The vulnerability was patched in version 1.1.4 to throw an error when an invalid _bsontype is detected during serialization.

Affected products

  • MongoDB bson before 1.1.4

Timeline

  • 2021-05-07: disclosed: GHSA-v8w9-2789-6hhr published
  • 2020-03-30: patched: CVE-2020-7610 reported; fix committed to js-bson

References

Related threats