Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9735

Опубликовано: 09 июн. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Версия от 8.3.0 (включая) до 8.3.3 (исключая)

EPSS

Процентиль: 2%
0.00119
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

CVSS3: 5.5
debian
3 месяца назад

MongoDB server may log authentication parameters, including credential ...

CVSS3: 5.5
github
3 месяца назад

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

EPSS

Процентиль: 2%
0.00119
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532