Vulnerability Details CVE-2021-23372
All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.4%
CVSS Severity
CVSS v3 Score 4.4
CVSS v2 Score 5.0
Products affected by CVE-2021-23372
-
cpe:2.3:a:mongo-express_project:mongo-express:0.10.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.11.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.11.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.11.2
-
cpe:2.3:a:mongo-express_project:mongo-express:0.11.3
-
cpe:2.3:a:mongo-express_project:mongo-express:0.12.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.13.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.14.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.14.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.15.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.16.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.16.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.17.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.17.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.17.2
-
cpe:2.3:a:mongo-express_project:mongo-express:0.17.3
-
cpe:2.3:a:mongo-express_project:mongo-express:0.17.4
-
cpe:2.3:a:mongo-express_project:mongo-express:0.17.5
-
cpe:2.3:a:mongo-express_project:mongo-express:0.2.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.2.2
-
cpe:2.3:a:mongo-express_project:mongo-express:0.2.3
-
cpe:2.3:a:mongo-express_project:mongo-express:0.27.4
-
cpe:2.3:a:mongo-express_project:mongo-express:0.29.10
-
cpe:2.3:a:mongo-express_project:mongo-express:0.3.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.3.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.3.2
-
cpe:2.3:a:mongo-express_project:mongo-express:0.3.3
-
cpe:2.3:a:mongo-express_project:mongo-express:0.3.4
-
cpe:2.3:a:mongo-express_project:mongo-express:0.32.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.33.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.34.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.35.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.37.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.37.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.37.2
-
cpe:2.3:a:mongo-express_project:mongo-express:0.38.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.39.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.39.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.39.2
-
cpe:2.3:a:mongo-express_project:mongo-express:0.4.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.40.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.41.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.42.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.42.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.42.2
-
cpe:2.3:a:mongo-express_project:mongo-express:0.42.3
-
cpe:2.3:a:mongo-express_project:mongo-express:0.43.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.43.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.44.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.45.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.46.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.46.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.47.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.48.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.48.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.49.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.5.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.50.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.51.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.51.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.51.2
-
cpe:2.3:a:mongo-express_project:mongo-express:0.52.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.52.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.52.2
-
cpe:2.3:a:mongo-express_project:mongo-express:0.53.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.54.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.6.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.7.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.7.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.8.0
-
cpe:2.3:a:mongo-express_project:mongo-express:0.8.1
-
cpe:2.3:a:mongo-express_project:mongo-express:0.9.0