EXPOSURES › CVE-2019-10758
CVE-2019-10758
HIGH ⌖ ON CISA KEV · EXPLOITEDMongoDB mongo-express versions before 0.54.0 suffered a remote code execution flaw via the toBSON method.
MongoDB mongo-express before 0.54.0 allowed attackers to execute arbitrary code through the toBSON method, enabling full system compromise. DIB organizations must ensure all database management interfaces are patched and monitored, as this flaw was actively exploited in the wild. Failure to patch exposes sensitive data and violates CMMC/NIST 800-171 requirements for timely vulnerability remediation.
Shame score — A known RCE vulnerability in a widely used database management tool was actively exploited in the wild, indicating negligent patching and poor supply-chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.
| PRODUCT | STATUS |
|---|---|
| MongoDB Atlas for Government MongoDB |
Authorized |