Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9735

Опубликовано: 09 июн. 2026
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Версия от 8.3.0 (включая) до 8.3.3 (исключая)

EPSS

Процентиль: 2%
0.00119
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

CVSS3: 5.5
debian
около 2 месяцев назад

MongoDB server may log authentication parameters, including credential ...

CVSS3: 5.5
github
около 2 месяцев назад

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.

EPSS

Процентиль: 2%
0.00119
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-532