1 results (0.014 seconds)

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0. Es posible que la entrada de cadenas de caracteres específicas no se validen apropiadamente en el controlador MongoDB Go al marshallar objetos Go en BSON. Un usuario malicioso podría usar un objeto Go con una cadena específica para inyectar potencialmente campos adicionales en los documentos ordenados. • https://github.com/mongodb/mongo-go-driver/releases/tag/v1.5.1 https://access.redhat.com/security/cve/CVE-2021-20329 https://bugzilla.redhat.com/show_bug.cgi?id=1971033 • CWE-20: Improper Input Validation CWE-1287: Improper Validation of Specified Type of Input •