Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-595w-9635-gr7c

Опубликовано: 13 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.8
CVSS3: 2.7

Описание

When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted. 

This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted. 

This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

EPSS

Процентиль: 11%
0.00204
Низкий

4.8 Medium

CVSS4

2.7 Low

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 2.7
ubuntu
3 месяца назад

When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted. This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

CVSS3: 2.7
nvd
3 месяца назад

When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted.  This issue impacts MongoDB Server v7.0 versions prior to 7.0.34, v8.0 versions prior to 8.0.23, v8.2 versions prior to 8.2.9 and v8.3 versions prior to 8.3.2.

CVSS3: 2.7
debian
3 месяца назад

When schema validation is enabled on a collection and an update or ins ...

EPSS

Процентиль: 11%
0.00204
Низкий

4.8 Medium

CVSS4

2.7 Low

CVSS3

Дефекты

CWE-532