PT-2022-10063 · Mongodb · Mongodb Extension For Vs Code

Published

2022-01-20

·

Updated

2024-09-17

·

CVE-2021-32039

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MongoDB Extension for VS Code versions prior to 0.7.0
Description The issue allows users with appropriate file access to obtain unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials can be used by malicious attackers to perform unauthorized actions.
Recommendations For versions prior to 0.7.0, update to version 0.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the binary file that stores user credentials to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BIT-MONGODB-2021-32039
CVE-2021-32039

Affected Products

Mongodb Extension For Vs Code