CISA Known Exploited Vulnerability

CVE-2019-10758

MongoDB · mongo-express

MongoDB mongo-express Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Unknown

CISA description

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.

Required action

Apply updates per vendor instructions.