Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93h4-p6c6-58pw

Опубликовано: 10 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.8
CVSS3: 5.5

Описание

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

EPSS

Процентиль: 2%
0.00119
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

CVSS3: 5.5
nvd
около 2 месяцев назад

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

CVSS3: 5.5
debian
около 2 месяцев назад

MongoDB server may log authentication parameters, including credential ...

EPSS

Процентиль: 2%
0.00119
Низкий

6.8 Medium

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-532