MongoDB C# Driver may publish events containing authentication-related data to a command listener configured by an application
Published May 13, 2021
4.9
MEDIUMCVSS 3.1
EPSS 0.62%
Description
Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when commands such as "saslStart", "saslContinue", "isMaster", "createUser", and "updateUser" are executed. Without due care, an application may inadvertently expose this authenticated-related information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default). This issue affects the MongoDB C# Driver v2.12 versions prior to and including 2.12.1.
Affected products
-
- Version 2.12StatusaffectedConstraints<=2.12.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| MongoDB Inc. | MongoDB C# Driver | unaffected |
|
- ≥ 2.12.0 · < 2.12.2
- 2.11.0
-
- Version 2.12StatusaffectedConstraints<=2.12.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| MongoDB | C\# Driver | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
1 other source (CVE.org) ▾
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:S/C:P/I:N/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jan 23, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (13 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.62% (0.00623) | 48.06th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.62% (0.00623) | 44.97th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.29% (0.00287) | 50.12th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00065) | 30.40th | v3 (v2023.03.01) |
| Jun 20, 2024 | 0.07% (0.00065) | 28.44th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00065) | 26.41th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.03% (0.09029) | 86.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.84% (0.01840) | 47.83th | v1 |
| Jan 6, 2022 | 1.84% (0.01840) | 47.32th | v1 |
| Jan 5, 2022 | 0.42% (0.00416) | 26.65th | v5 (v2026.06.15) |
| May 13, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (4)
- https://github.com/advisories/GHSA-p9rv-qgqw-jx2w Advisory
- https://github.com/mongodb/mongo-csharp-driver/commit/1f1a526e93ed7aa254759704b19f5ee66a3af365
- https://jira.mongodb.org/browse/CSHARP-3521 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-20331
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-p9rv-qgqw-jx2w | Advisory | |
| https://github.com/mongodb/mongo-csharp-driver/commit/1f1a526e93ed7aa254759704b19f5ee66a3af365 | ||
| https://jira.mongodb.org/browse/CSHARP-3521 | x_refsource_CONFIRMIssue TrackingPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-20331 |
Change history (0)
No recorded changes yet.