KEVIntel
9.9
CVSS
Critical

CVE-2019-10758

PUBLISHED

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to...

Exploited in the wild Remote Low complexity No user interaction
Vendor
mongo-express
Product
mongo-express
Published
Dec 24, 2019
EPSS

Description

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

cisa nuclei_scanner nessus_scanner

CVSS scores

CVSS v3.1 9.9 Critical

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS v2.0 9.0

AV:N/AC:L/Au:S/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2021-12-10 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Dec 10, 2021
CISA Dec 10, 2021

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

ossf-cve-benchmark/CVE-2019-10758

github · Created 2020-12-01 09:18:57 UTC · 1 stars

lp008/CVE-2019-10758

github · Created 2020-01-05 14:05:56 UTC · 5 stars

CVE-2019-10758

masahiro331/CVE-2019-10758

github · Created 2019-12-26 06:58:56 UTC · 111 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Added to KEVIntel

  • Detected by Nessus

  • Detected by Nuclei