You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Path to vulnerable library: /canner/.gradle/caches/modules-2/files-2.1/org.mongodb/mongo-java-driver/3.10.1/d2a7008196b34b735cfc47d8609ebe47f62cd8a1/mongo-java-driver-3.10.1.jar
Path to vulnerable library: /canner/.gradle/caches/modules-2/files-2.1/org.mongodb/mongo-java-driver/3.10.1/d2a7008196b34b735cfc47d8609ebe47f62cd8a1/mongo-java-driver-3.10.1.jar
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don’t use Field Level Encryption.
The MongoDB Java Driver uber-artifact, containing the legacy driver, the mongodb-driver, mongodb-driver-core, and bson
Library home page: http://www.mongodb.org
Path to dependency file: /build.gradle
Path to vulnerable library: /canner/.gradle/caches/modules-2/files-2.1/org.mongodb/mongo-java-driver/3.10.1/d2a7008196b34b735cfc47d8609ebe47f62cd8a1/mongo-java-driver-3.10.1.jar
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - mongo-java-driver-3.10.1.jar
The MongoDB Java Driver uber-artifact, containing the legacy driver, the mongodb-driver, mongodb-driver-core, and bson
Library home page: http://www.mongodb.org
Path to dependency file: /build.gradle
Path to vulnerable library: /canner/.gradle/caches/modules-2/files-2.1/org.mongodb/mongo-java-driver/3.10.1/d2a7008196b34b735cfc47d8609ebe47f62cd8a1/mongo-java-driver-3.10.1.jar
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don’t use Field Level Encryption.
Publish Date: 2021-02-25
URL: CVE-2021-20328
CVSS 3 Score Details (6.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-rghw-6px2-fgwc
Release Date: 2021-02-25
Fix Resolution: 3.11.3
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: