Vulnerabilities > CVE-2021-23372 - Improper Check for Unusual or Exceptional Conditions vulnerability in Mongo-Express Project Mongo-Express

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
mongo-express-project
CWE-754

Summary

All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.

Vulnerable Configurations

Part Description Count
Application
Mongo-Express_Project
1