漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
MongoDB Rust Driver may publish events containing authentication-related data to a connection pool event listener configured by an application
漏洞信息
Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is emitted when the pool is created. The user's logging infrastructure could then potentially ingest these events and unexpectedly leak the credentials. Note that such monitoring is not enabled by default. This issue affects MongoDB Rust Driver version 2.0.0-alpha, MongoDB Rust Driver version 2.0.0-alpha1 and MongoDB Rust Driver version 1.0.0 through to and including 1.2.1
漏洞信息
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
漏洞
信息暴露
漏洞
Rust 信息泄露漏洞
漏洞信息
Rust是Mozilla基金会的一款通用、编译型编程语言。 MongoDB Rust Driver 存在信息泄露漏洞,该漏洞源于特定的MongoDB Rust Driver版本可以包含连接池使用的凭证,用于在创建连接池时发出的监视事件中验证连接。然后,用户的日志基础设施可能摄取这些事件并意外泄漏的凭据。 请注意,默认情况下不启用此类监控。
漏洞信息
N/A
漏洞
N/A