Описание
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 7.0.0 (включая) до 7.0.35 (исключая)Версия от 8.0.0 (включая) до 8.0.24 (исключая)Версия от 8.2.0 (включая) до 8.2.10 (исключая)Версия от 8.3.0 (включая) до 8.3.3 (исключая)
Одно из
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 1%
0.00109
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-532
Связанные уязвимости
CVSS3: 5.5
ubuntu
3 месяца назад
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
CVSS3: 5.5
debian
3 месяца назад
The ldapQueryPassword parameter, when set through the runtime setParam ...
CVSS3: 5.5
github
3 месяца назад
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
EPSS
Процентиль: 1%
0.00109
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-532