Skip to content
COOEY

EXPOSURES › CVE-2019-10758

CVE-2019-10758

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-10758 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

MongoDB mongo-express versions before 0.54.0 suffered a remote code execution flaw via the toBSON method.

MongoDB mongo-express before 0.54.0 allowed attackers to execute arbitrary code through the toBSON method, enabling full system compromise. DIB organizations must ensure all database management interfaces are patched and monitored, as this flaw was actively exploited in the wild. Failure to patch exposes sensitive data and violates CMMC/NIST 800-171 requirements for timely vulnerability remediation.

Shame score — A known RCE vulnerability in a widely used database management tool was actively exploited in the wild, indicating negligent patching and poor supply-chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
MongoDB Atlas for Government
MongoDB
Authorized