Specific cstrings input may not be properly validated in the Go Driver
Vulnerability Description
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-20329
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Hugo Ferrando Seage
More from MongoDB Inc.
View All →Affected Vendor
MongoDB Inc.
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.