Vulnerabilities > Mongodb > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-08-02 | CVE-2021-20332 | Unspecified vulnerability in Mongodb Rust Driver Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. | 4.4 |
2021-07-23 | CVE-2021-20333 | Improper Encoding or Escaping of Output vulnerability in Mongodb Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. | 5.3 |
2021-06-10 | CVE-2021-20329 | Improper Input Validation vulnerability in Mongodb GO Driver Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. | 6.5 |
2021-05-13 | CVE-2021-20331 | Information Exposure vulnerability in Mongodb C# Driver 2.11.0/2.12.0/2.12.1 Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. | 4.9 |
2021-04-30 | CVE-2021-20326 | Incorrect Permission Assignment for Critical Resource vulnerability in Mongodb A user authorized to performing a specific type of find query may trigger a denial of service. | 6.5 |
2021-04-12 | CVE-2020-7924 | Improper Certificate Validation vulnerability in Mongodb Database Tools and Mongomirror Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. | 6.5 |
2021-03-01 | CVE-2018-25004 | Improper Input Validation vulnerability in Mongodb A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. | 4.9 |
2021-03-01 | CVE-2020-7929 | Unspecified vulnerability in Mongodb A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. | 6.5 |
2021-02-25 | CVE-2021-20328 | Improper Certificate Validation vulnerability in multiple products Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. | 6.8 |
2021-02-25 | CVE-2021-20327 | Improper Certificate Validation vulnerability in Mongodb Libmongocrypt 1.2.0 A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. | 6.8 |