First published: Tue Mar 16 2021(Updated: )
MongoDB is a higly-scalable document database. The Debezium MongoDB connector includes Java driver to access a MongoDB database.<br>Security Fix(es):<br><li> mongodb-driver: mongo-java-driver: client-side field level encryption not verifying KMS host name (CVE-2021-20328)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Integration Debezium |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:0871 is classified as moderate.
To fix RHSA-2021:0871, ensure that you have updated to the latest versions of the impacted software that include the relevant security fixes.
RHSA-2021:0871 addresses a vulnerability in the MongoDB driver related to client-side field level encryption not verifying the KMS host name, identified as CVE-2021-20328.
The affected component in RHSA-2021:0871 is the mongo-java-driver used by the Debezium MongoDB connector.
Currently, the best approach for addressing RHSA-2021:0871 is to apply the recommended updates rather than relying on workarounds.