Unrated severityNVD Advisory· Published Jul 23, 2021· Updated Sep 17, 2024
Server log entry spoofing via newline injection
CVE-2021-20333
Description
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10.
Affected products
2- MongoDB Inc./MongoDB Serverv5Range: 3.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- jira.mongodb.org/browse/SERVER-50605mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.