CVE-2021-20332 - CVE House
Back to Database
Status published Medium CVE-2021-20332

MongoDB Rust Driver may publish events containing authentication-related data to a connection pool event listener configured by an application

Vulnerability Description

Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user's logging infrastructure could then potentially ingest these events and unexpectedly leak the credentials. Note that such monitoring is not enabled by default. This issue affects MongoDB Rust Driver version 2.0.0-alpha, MongoDB Rust Driver version 2.0.0-alpha1 and MongoDB Rust Driver version 1.0.0 through to and including 1.2.1

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-20332

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

MongoDB Inc.

View all reports →

Affected Software

MongoDB Rust Driver
Vulnerable Versions:
2.0.0-alpha, 2.0.0-alpha1, 1.0.0

Timeline

Official Publish: August 2nd, 2021
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N

Weaknesses (CWE)