ZeroHour

CVE-2021-20329

CVSS 3.1
6.5 medium
EPSS
<1%p60
Published
()
Modified
Description

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.

Vendors
mongodb
Products
go driver
Weakness
CWE-1287, CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.