Skip to content

Latest commit

 

History

History
17 lines (11 loc) · 940 Bytes

CVE-2021-20332.md

File metadata and controls

17 lines (11 loc) · 940 Bytes

Description

Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user's logging infrastructure could then potentially ingest these events and unexpectedly leak the credentials. Note that such monitoring is not enabled by default.

POC

Reference

No PoCs from references.

Github