PT-2023-4650 · Mongodb+2 · Mongodb Php Driver+5

Daria Pardue

+1

·

Published

2023-08-29

·

Updated

2025-05-20

·

CVE-2021-32050

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MongoDB C Driver versions 1.0.0 through 1.17.7 MongoDB PHP Driver versions 1.0.0 through 1.9.2 MongoDB Swift Driver versions 1.0.0 through 1.1.1 MongoDB Node.js Driver 3.6 versions 3.6 through 3.6.10 MongoDB Node.js Driver 4.0 versions 4.0 through 4.17.0 MongoDB Node.js Driver 5.0 versions 5.0 through 5.8.0 MongoDB C++ Driver versions prior to 3.7.0
Description Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature, which is not enabled by default.
Recommendations For MongoDB C Driver versions 1.0.0 through 1.17.7, update to version 1.17.7 or later. For MongoDB PHP Driver versions 1.0.0 through 1.9.2, update to version 1.9.2 or later. For MongoDB Swift Driver versions 1.0.0 through 1.1.1, update to version 1.1.1 or later. For MongoDB Node.js Driver 3.6 versions 3.6 through 3.6.10, update to version 3.6.10 or later. For MongoDB Node.js Driver 4.0 versions 4.0 through 4.17.0, update to version 4.17.0 or later. For MongoDB Node.js Driver 5.0 versions 5.0 through 5.8.0, update to version 5.8.0 or later. For MongoDB C++ Driver versions prior to 3.7.0, update to version 3.7.0 or later. As a temporary workaround, consider disabling the command listener feature until a patch is available.

Fix

Information Disclosure

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2023-05059
CVE-2021-32050
DLA-4175-1
GHSA-VXVM-QWW3-2FH7

Affected Products

Astra Linux
Debian
Mongodb C Driver
Mongodb Node.Js Driver
Mongodb Php Driver
Mongodb Swift Driver