QID 982759
QID 982759: Nodejs (npm) Security Update for mongodb-query-parser (GHSA-hxmg-hm46-cf62)
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hxmg-hm46-cf62 for updates pertaining to this vulnerability.
Vendor References
- GHSA-hxmg-hm46-cf62 -
github.com/advisories/GHSA-hxmg-hm46-cf62
CVEs related to QID 982759
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hxmg-hm46-cf62 | mongodb-query-parser |
|