Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20329

Опубликовано: 10 июн. 2021
Источник: nvd
CVSS3: 6.8
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mongodb:go_driver:*:*:*:*:*:mongodb:*:*
Версия до 1.5.0 (включая)

EPSS

Процентиль: 41%
0.00194
Низкий

6.8 Medium

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-1287
CWE-20

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 4 лет назад

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.

CVSS3: 6.5
redhat
почти 5 лет назад

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.

CVSS3: 6.8
github
больше 4 лет назад

go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSON

EPSS

Процентиль: 41%
0.00194
Низкий

6.8 Medium

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-1287
CWE-20