Moderate severityNVD Advisory· Published Apr 13, 2021· Updated Sep 16, 2024
Denial of Service (DoS)
CVE-2021-23372
Description
All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mongo-expressnpm | <= 0.54.0 | — |
Affected products
2- mongo-express/mongo-expressdescription
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-m2r3-8492-vx59ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23372ghsaADVISORY
- snyk.io/vuln/SNYK-JS-MONGOEXPRESS-1085403ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.