Echo: MongoDB.Bson: security update to 2.13.0+echo.1

high Tenable Self-Hosted Container Security Plugin ID 474017

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Under very specific circumstances (see Required configuration section below), a privileged user is able to
cause arbitrary code to be executed which may cause further disruption to services. This is specific to
applications written in C#. This affects all MongoDB .NET/C# Driver versions prior to and including
v2.18.0 Following configuration must be true for the vulnerability to be applicable: * Application must
written in C# taking arbitrary data from users and serializing data using _t without any validation AND *
Application must be running on a Windows host using the full .NET Framework, not .NET Core AND *
Application must have domain model class with a property/field explicitly of type System.Object or a
collection of type System.Object (against MongoDB best practice) AND * Malicious attacker must have
unrestricted insert access to target database to add a _t discriminator."Following configuration must be
true for the vulnerability to be applicable (CVE-2022-48282)

Solution

Update the MongoDB.Bson library and its related packages to version 2.13.0+echo.1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2022-48282

Plugin Details

Severity: High

ID: 474017

Version: Revision 1.1

Type: Local

Published: 10/9/2026

Updated: 10/9/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

CVSS v2

Risk Factor: High

Base Score: 8.3

Temporal Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

CVSS Score Source: CVE-2022-48282

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 2/21/2023

Reference Information

CVE: CVE-2022-48282