MongoDB Vulnerabilities and Affected Products
Vulnerabilities associated with c\#_driver.
Products
Clear product- MongoDB Server65 vulnerabilities
- mongodb9 vulnerabilities
- BI Connector ODBC Driver6 vulnerabilities
- Atlas SQL ODBC Driver2 vulnerabilities
- Schema Builder CLI2 vulnerabilities
- BSON::XS1 vulnerability
- C Driver1 vulnerability
- c\#_driver1 vulnerability
- c_driver1 vulnerability
- java_driver1 vulnerability
- Mongo-c-driver1 vulnerability
- mongo-express1 vulnerability
- MongoDB and MongoDB Server1 vulnerability
- MongoDB Compass1 vulnerability
- MongoDB Driver1 vulnerability
- mongodb_server1 vulnerability
- PHP Driver1 vulnerability
- Rust Driver1 vulnerability
- rust_driver1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-20331MEDIUM | MongoDB C# Driver may publish events containing authentication-related data to a command listener configured by an applicationSpecific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when commands such as "saslStart", "saslContinue", "isMaster", "createUser", and "updateUser" are executed. Without due care, an application may inadvertently expose this authenticated-related information, e.g., by writing it to a log file. This issue only arises if an applicat… CWE-200May 13, 2021 | CVSS4.2v3.1 | EPSS0.623% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |