You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers up to (and including) 1.5.0.
CVE-2021-20329 - Medium Severity Vulnerability
go.mongodb.org/mongo-driver/bson-v1.0.3
The Go driver for MongoDB
Dependency Hierarchy:
go.mongodb.org/mongo-driver/bson/bsonrw-v1.0.3
The Go driver for MongoDB
Dependency Hierarchy:
go.mongodb.org/mongo-driver/x/bsonx/bsoncore-v1.0.3
The Go driver for MongoDB
Dependency Hierarchy:
Found in base branch: master
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers up to (and including) 1.5.0.
Publish Date: 2021-06-10
URL: CVE-2021-20329
Base Score Metrics:
Type: Upgrade version
Release Date: 2021-06-10
Fix Resolution: v1.5.1
The text was updated successfully, but these errors were encountered: