Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gq2v-frgg-2m9q

Опубликовано: 27 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.1
CVSS3: 4.4

Описание

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.

EPSS

Процентиль: 1%
0.0009
Низкий

4.1 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 4.4
nvd
26 дней назад

In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.

EPSS

Процентиль: 1%
0.0009
Низкий

4.1 Medium

CVSS4

4.4 Medium

CVSS3

Дефекты

CWE-532