漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
MongoDB C# Driver may publish events containing authentication-related data to a command listener configured by an application
漏洞信息
Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when commands such as "saslStart", "saslContinue", "isMaster", "createUser", and "updateUser" are executed. Without due care, an application may inadvertently expose this authenticated-related information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C# Driver v2.12 versions prior to and including 2.12.1.
漏洞信息
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
漏洞
信息暴露
漏洞
Mongodb Server 信息泄露漏洞
漏洞信息
Mongodb Server是美国Mongodb公司的一套开源的NoSQL数据库。该数据库提供面向集合的存储、动态查询、数据复制及自动故障转移等功能。 MongoDB C# Driver 2.12版本到2.12.1版本存在安全漏洞。该漏洞源于程序发布的事件可能包含对安全性敏感的数据,如果没有适当的注意,应用程序可能会无意间公开此已验证的相关信息。
漏洞信息
N/A
漏洞
N/A