Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f6mq-5m25-4r72

Опубликовано: 15 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSON

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers up to (and including) 1.5.0.

Пакеты

Наименование

go.mongodb.org/mongo-driver

go
Затронутые версииВерсия исправления

< 1.5.1

1.5.1

EPSS

Процентиль: 41%
0.00194
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-1287
CWE-20

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 4 лет назад

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.

CVSS3: 6.5
redhat
почти 5 лет назад

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.

CVSS3: 6.8
nvd
больше 4 лет назад

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.

EPSS

Процентиль: 41%
0.00194
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-1287
CWE-20