Description
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.
Remediation
References
https://snyk.io/vuln/SNYK-JS-BSON-561052
Related Vulnerabilities
CVE-2021-23444 Vulnerability in npm package jointjs
CVE-2023-43494 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2022-36437 Vulnerability in maven package com.hazelcast:hazelcast-enterprise
CVE-2023-25330 Vulnerability in maven package com.baomidou:mybatis-plus-extension
CVE-2023-5654 Vulnerability in npm package react-devtools-core