CVE-2021-20329
Summary
| CVE | CVE-2021-20329 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-10 17:15:00 UTC |
| Updated | 2024-01-23 16:15:00 UTC |
| Description | Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers up to (and including) 1.5.0. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release MongoDB Go Driver 1.5.1 · mongodb/mongo-go-driver · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Hugo Ferrando Seage
Legacy QID Mappings
- 982056 Go (go) Security Update for go.mongodb.org/mongo-driver (GHSA-f6mq-5m25-4r72)