Impact
In the MongoDB Entity Framework Core Provider, enabling DEBUG logging or using a malformed MongoDB connection string causes application logs to capture sensitive data such as passwords and AWS secure access keys. When this logging mode is active, the provider does not filter or redact credentials before writing them to the log stream, resulting in accidental disclosure of confidential information.
Affected Systems
The vulnerability impacts MongoDB Inc.’s MongoDB Entity Framework Core Provider. No specific version range is provided in the advisory, so all versions of this provider may be affected until a patch is released.
Risk and Exploitability
The CVSS score of 5.7 indicates a medium severity threat. The EPSS score is less than 1%, suggesting the likelihood of exploitation is relatively low, and the vulnerability is not listed in CISA’s KEV catalog. Attackers who can trigger DEBUG logging or supply a malformed connection string—such as developers, automated build systems, or privileged application components—can cause sensitive data to be written to logs that may be accessed by third parties or retained for extended periods. Once revealed, the information may be leveraged for credential theft or further compromise of the target environment.
OpenCVE Enrichment