Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.
2021-06-10T17:15:08.047
2024-11-21T05:46:23.420
Modified
CVSSv3.1: 6.8 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9