CVE-2019-10758: Remote Code Execution Vulnerability in NPM mongo-express
(updated )
Remote code execution on the host machine by any authenticated user.
References
- github.com/advisories/GHSA-h47j-hc6x-h3qq
- github.com/mongo-express/mongo-express/commit/7d365141deadbd38fa961cd835ce68eab5731494
- github.com/mongo-express/mongo-express/pull/522
- github.com/mongo-express/mongo-express/security/advisories/GHSA-h47j-hc6x-h3qq
- nvd.nist.gov/vuln/detail/CVE-2019-10758
- snyk.io/vuln/SNYK-JS-MONGOEXPRESS-473215
Detect and mitigate CVE-2019-10758 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →