Описание
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.0.0 (включая) до 7.0.35 (исключая)Версия от 8.0.0 (включая) до 8.0.24 (исключая)Версия от 8.2.0 (включая) до 8.2.10 (исключая)Версия от 8.3.0 (включая) до 8.3.3 (исключая)
Одно из
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 1%
0.00109
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-532
Связанные уязвимости
CVSS3: 5.5
ubuntu
около 2 месяцев назад
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
CVSS3: 5.5
debian
около 2 месяцев назад
The ldapQueryPassword parameter, when set through the runtime setParam ...
CVSS3: 5.5
github
около 2 месяцев назад
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
EPSS
Процентиль: 1%
0.00109
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-532