Описание
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.
A flaw was found in the MongoDB Go Driver. The Client.BulkWrite operation does not properly validate database names, allowing a specially crafted name with reserved characters to redirect write operations. This vulnerability could enable an attacker to modify or corrupt data in unintended databases and collections.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Pipelines | openshift-pipelines-client | Affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-chains-controller-rhel8 | Affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-chains-controller-rhel9 | Affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-cli-tkn-rhel8 | Affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-cli-tkn-rhel9 | Affected | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-opc-rhel9 | Affected | ||
| Red Hat Edge Manager 1 | flightctl | Affected | ||
| Red Hat Edge Manager 1 | rhem/flightctl-alert-exporter-rhel10 | Affected | ||
| Red Hat Edge Manager 1 | rhem/flightctl-alert-exporter-rhel9 | Affected | ||
| Red Hat Edge Manager 1 | rhem/flightctl-alertmanager-proxy-rhel10 | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.
The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.
The MongoDB Go Driver's client-level bulk write operation may accept a ...
7.5 High
CVSS3