Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1314 | Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0. |
Github GHSA |
GHSA-f6mq-5m25-4r72 | go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSON |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 16 Sep 2024 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0. | Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0. |
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2024-09-16T22:55:51.498Z
Reserved: 2020-12-17T00:00:00
Link: CVE-2021-20329
No data.
Status : Modified
Published: 2021-06-10T17:15:08.047
Modified: 2024-11-21T05:46:23.420
Link: CVE-2021-20329
OpenCVE Enrichment
No data.
EUVD
Github GHSA