Lucene search

K
osvGoogleOSV:GO-2021-0112
HistoryJul 28, 2021 - 6:08 p.m.

Improper input validation in go.mongodb.org/mongo-driver

2021-07-2818:08:05
Google
osv.dev
23

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.9%

Due to improper input sanitization when marshalling Go objects into BSON, a maliciously constructed Go structure could allow an attacker to inject additional fields into a MongoDB document. Users are affected if they use this package to handle untrusted user input.

CPENameOperatorVersion
go.mongodb.org/mongo-driverlt1.5.1

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.9%