First published: Mon Aug 02 2021(Updated: )
Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user's logging infrastructure could then potentially ingest these events and unexpectedly leak the credentials. Note that such monitoring is not enabled by default.
Credit: cna@mongodb.com cna@mongodb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mongodb Rust Driver | >=1.0.0<=1.2.1 | |
Mongodb Rust Driver | =2.0.0-alpha | |
Mongodb Rust Driver | =2.0.0-alpha1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20332 is a vulnerability in specific versions of the MongoDB Rust Driver that can potentially leak credentials used for authentication.
The severity of CVE-2021-20332 is medium with a CVSS score of 4.4.
CVE-2021-20332 affects specific versions of the MongoDB Rust Driver by potentially leaking credentials used for authentication.
Versions 1.0.0 to 1.2.1, 2.0.0-alpha, and 2.0.0-alpha1 of the MongoDB Rust Driver are affected by CVE-2021-20332.
CVE-2021-20332 falls under the CWE category 200 - Information Exposure.