CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-24391

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1610%
EPSS Percentile36.78th
Published2021年3月30日
Last Modified2024年11月21日

Vulnerability Description

mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.

Affected Platforms (CPE)

📦
Mongo Express Project

Mongo Express

<= 0.54.0

References & Advisories

関連する脆弱性情報