Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0
References
| Link | Resource |
|---|---|
| https://github.com/mongodb-js/vscode/releases/tag/v0.8.0 | Release Notes Third Party Advisory |
| https://jira.mongodb.org/browse/VSCODE-313 | Issue Tracking Vendor Advisory |
| https://github.com/mongodb-js/vscode/releases/tag/v0.8.0 | Release Notes Third Party Advisory |
| https://jira.mongodb.org/browse/VSCODE-313 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2022-01-20 15:15
Updated : 2024-11-21 06:06
NVD link : CVE-2021-32039
Mitre link : CVE-2021-32039
CVE.ORG link : CVE-2021-32039
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-522
Insufficiently Protected Credentials
