{"id":"CVE-2019-2391","details":"Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour including data disclosure. This issue affects: MongoDB Inc. js-bson library version 1.1.3 and prior to.","aliases":["GHSA-4jwp-vfvf-657p"],"modified":"2026-07-08T16:28:07.966654Z","published":"2020-03-31T14:15:14.173Z","references":[{"type":"FIX","url":"https://github.com/mongodb/js-bson/releases/tag/v1.1.4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/js-bson","events":[{"introduced":"0"},{"fixed":"6e782dac6a110509097077ee5edd311977f32522"}],"database_specific":{"cpe":"cpe:2.3:a:mongodb:js-bson:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.1.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.1.3","v1.1.2","v1.1.0","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","V1.0.4","V1.0.3","V1.0.2","V1.0.1","V1.0.0","V0.5.7","V0.5.6","V0.5.5","V0.5.4","V0.5.3","V0.5.2","V0.5.1","V0.5.0","V0.4.23","V0.4.22","V0.4.21","V0.4.20","V0.4.19","V0.4.18","V0.4.17","V0.4.16","V0.4.15","V0.4.14","V0.4.13","V0.4.12","V0.4.11","V0.4.10","V0.4.9","V0.4.8","V0.2.21","V0.4.7","V0.4.6","V0.4.5","V0.4.4","V0.4.3","V0.4.2","V0.4.1","V0.4.0","V0.3.2","V0.3.1","V0.3.0","V0.2.20","V0.2.19","V0.2.18","V0.2.17","V0.2.16","V0.2.15","V0.2.14","V0.2.13","V0.2.11","V0.2.10","V0.2.9","V0.2.8","V0.2.6","V0.2.5","V0.2.2","V0.2.1","V0.2.0","V0.1.9","V0.1.4","V0.1.2","V0.1.0","V0.0.9","V0.0.8","V0.0.6","V0.0.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-2391.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}