Skip to main content

Uncaught Exception in mongodb-0.9.6

Cxd6c215a2-86bd

  • mongodb-0.9.6
  • mongodb-0.9.7
  • mongodb
Severity High
Score 7.5/10

Summary

Versions of node-mongodb prior to 3.1.13 are vulnerable to Denial of Service. The package fails to properly catch an exception when a collection name is invalid and the DB does not exist, crashing the application.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-248 - Uncaught Exception

An exception is thrown from a function, but it is not caught.

Advisory Timeline

  • Published