Input validation error in MongoDB Go Driver - CVE-2021-20329

 

Input validation error in MongoDB Go Driver - CVE-2021-20329

Published: March 29, 2023


Vulnerability identifier: #VU74181
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20329
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate data

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can inject additional fields into marshalled documents and manipulate data in the database.


Affected software

MongoDB Go Driver
OpenShift Service Mesh
OpenShift Virtualization
Red Hat OpenShift Container Platform

How to mitigate CVE-2021-20329

Install updates from vendor's website.

MongoDB Go Driver - update to 1.5.1
OpenShift Service Mesh - update to 2.2.7
Red Hat OpenShift Container Platform - addressed in versions 4.9.59, 4.10.55, 4.10.56, 4.11.34, 4.12.9, 4.13.0, 4.13.10, 4.13.29, 4.14.0
OpenShift Virtualization - update to 4.14.0

External References

Related Security Bulletins