← Back to CVE List
Vulnerability Intelligence Report
Denial of Service (DoS)

CVE-2021-23372

All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.

No Active Exploit Signals
CVSS Base Score
4.4
MEDIUM
Exploitability:0.8
Impact Score:3.6
EPSS Probability:0.88%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
mongo-express_project mongo-express all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.878%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySnyk · Open Source · UK
Reserved2021-01-08T00:00:00
Published2021-04-13T15:20:12
Patch Date2021-04-13
Last Updated2024-09-16T19:09:17

LINK COPIED TO CLIPBOARD