CVE-2020-7610 is a vulnerability in MongoDB Bson
Published on March 30, 2020
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.
Products Associated with CVE-2020-7610
Want to know whenever a new CVE is published for MongoDB Bson? stack.watch will email you.
Exploit Probability
EPSS
2.24%
Percentile
81.47%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.