Lucene search

K
osvGoogleOSV:GHSA-F6MQ-5M25-4R72
HistoryJun 15, 2021 - 4:08 p.m.

go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSON

2021-06-1516:08:16
Google
osv.dev
12

0.001 Low

EPSS

Percentile

22.9%

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers up to (and including) 1.5.0.

CPENameOperatorVersion
go.mongodb.org/mongo-driverlt1.5.1

0.001 Low

EPSS

Percentile

22.9%