Some MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an application
Published Aug 29, 2023
7.5
HIGHCVSS 3.1
EPSS 0.65%
Description
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.
Without due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).
This issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).
Affected products
-
- Version 1.0.0StatusaffectedConstraints<1.17.7
- Version
-
- Version 3.0.0StatusaffectedConstraints<3.7.0
- Version
-
- Version 3.6StatusaffectedConstraints<3.6.10
- Version 4.0StatusaffectedConstraints<4.17.0
- Version 5.0StatusaffectedConstraints<5.8.0
- Version
-
- Version 1.0.0StatusaffectedConstraints<1.9.2
- Version
-
- Version 1.0.0StatusaffectedConstraints<1.1.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| MongoDB Inc | MongoDB C Driver | unaffected |
| ||||||||||||
| MongoDB Inc | MongoDB C++ Driver | unaffected |
| ||||||||||||
| MongoDB Inc | MongoDB Node.js Driver | unaffected |
| ||||||||||||
| MongoDB Inc | MongoDB PHP Driver | unaffected |
| ||||||||||||
| MongoDB Inc | MongoDB Swift Driver | unaffected |
|
- ≥ 1.0.0 · < 1.17.7
- ≥ 1.0.0 · < 1.17.7
- ≥ 3.6 · < 3.6.10
- ≥ 4.0 · < 4.17.0
- ≥ 5.0 · < 5.8.0
- ≥ 1.0.0 · < 1.9.2
- ≥ 1.0.0 · < 1.1.1
No data.
No Red Hat product state for this CVE.
mongodb/mongodb
Packagist
Introduced 1.0.0 Fixed 1.9.2mongodb
npm
Introduced 3.6.0 Fixed 3.6.10mongodb
npm
Introduced 4.0.0 Fixed 4.17.0mongodb
npm
Introduced 5.0.0 Fixed 5.8.0github.com/mongodb/mongo-swift-driver
SwiftURL
Introduced 1.0.0 Fixed 1.1.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Packagist | mongodb/mongodb | 1.0.0 | 1.9.2 |
| npm | mongodb | 3.6.0 | 3.6.10 |
| npm | mongodb | 4.0.0 | 4.17.0 |
| npm | mongodb | 5.0.0 | 5.8.0 |
| SwiftURL | github.com/mongodb/mongo-swift-driver | 1.0.0 | 1.1.1 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
1 other source (GHSA) ▾
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (7 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.65% (0.00646) | 49.08th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.49% (0.00492) | 38.14th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.08% (0.00080) | 21.14th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.15% (0.00155) | 53.18th | v3 (v2023.03.01) |
| Oct 7, 2023 | 0.07% (0.00071) | 29.26th | v3 (v2023.03.01) |
| Sep 8, 2023 | 0.06% (0.00060) | 23.77th | v3 (v2023.03.01) |
| Aug 30, 2023 | 0.04% (0.00045) | 12.21th | v3 (v2023.03.01) |
References (13)
- https://github.com/advisories/GHSA-vxvm-qww3-2fh7 Advisory
- https://github.com/mongodb/mongo-php-driver/commit/4495de8313c0d313e4dde906fc7aedf998ee3748
- https://github.com/mongodb/mongo-php-driver/pull/1235
- https://github.com/mongodb/mongo-swift-driver/pull/643
- https://github.com/mongodb/node-mongodb-native/commit/8c8b4c3b8c55f10fb96f63d3bbfa5d408b4ed7d0
- https://jira.mongodb.org/browse/CDRIVER-3797 Issue TrackingPatchVendor Advisory
- https://jira.mongodb.org/browse/CXX-2028 Issue TrackingPatchVendor Advisory
- https://jira.mongodb.org/browse/NODE-3356 Issue TrackingPatchVendor Advisory
- https://jira.mongodb.org/browse/PHPC-1869 Issue TrackingPatchVendor Advisory
- https://jira.mongodb.org/browse/SWIFT-1229 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2025/05/msg00027.html
- https://nvd.nist.gov/vuln/detail/CVE-2021-32050
- https://security.netapp.com/advisory/ntap-20231006-0001
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-vxvm-qww3-2fh7 | Advisory | |
| https://github.com/mongodb/mongo-php-driver/commit/4495de8313c0d313e4dde906fc7aedf998ee3748 | ||
| https://github.com/mongodb/mongo-php-driver/pull/1235 | ||
| https://github.com/mongodb/mongo-swift-driver/pull/643 | ||
| https://github.com/mongodb/node-mongodb-native/commit/8c8b4c3b8c55f10fb96f63d3bbfa5d408b4ed7d0 | ||
| https://jira.mongodb.org/browse/CDRIVER-3797 | Issue TrackingPatchVendor Advisory | |
| https://jira.mongodb.org/browse/CXX-2028 | Issue TrackingPatchVendor Advisory | |
| https://jira.mongodb.org/browse/NODE-3356 | Issue TrackingPatchVendor Advisory | |
| https://jira.mongodb.org/browse/PHPC-1869 | Issue TrackingPatchVendor Advisory | |
| https://jira.mongodb.org/browse/SWIFT-1229 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2025/05/msg00027.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2021-32050 | ||
| https://security.netapp.com/advisory/ntap-20231006-0001 |
Change history (0)
No recorded changes yet.