TROYANOSYVIRUS
Retour aux CVEs

CVE-2021-20329

MEDIUM
6.8

Description

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.

Details CVE

Score CVSS v3.16.8
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisLOW
Interaction utilisateurNONE
Publie6/10/2021
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

mongodb:go_driver

Faiblesses (CWE)

CWE-1287CWE-20

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.