Showing 1 vulnerability on this page for MongoDB Driver

Signals CISA KEV Ransomware Nuclei
MongoDB vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and requires no special privileges to trigger. A party able to read the affected application's logs or downstream log-aggregation storage could recover the credential and reuse it to authenticate to the associated network infrastr

CWE-532Aug 11, 2026
CVSS8.2v4.0EPSS0.113%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX