-
Type:
Task
-
Resolution: Done
-
Priority:
Critical - P2
-
Affects Version/s: None
-
Component/s: None
-
None
-
0.5
-
Dotnet Drivers
-
Not Needed
-
None
-
None
-
None
-
None
-
None
-
None
Summary
Secrets placed in connection-string options, such as AWS session tokens or proxy passwords, are written unredacted to application logs; only the password field is masked.
Impact
Database, cloud (AWS), and proxy credential material is persisted to application logs where lower-trust log readers and downstream log pipelines can recover it and authenticate as the application.
Severity: high (upper bound critical)
Exploitability: exploitable — Deterministic — every context initialization emits the unredacted fragment to logs by default; exploitation is simply reading the logs, with the attacker controlling nothing.
Customer data: credentials, tokens, secrets (logs)
Location
- src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:269 in SanitizeConnectionStringForLogging
- src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:324 in CreateLogFragment
- src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:268 in SanitizeConnectionStringForLogging
- src/MongoDB.EntityFrameworkCore/Extensions/MongoDbContextOptionsExtensions.cs:73 in UseMongoDB
- src/MongoDB.EntityFrameworkCore/Extensions/MongoDbContextOptionsExtensions.cs:118 in UseMongoDB
- src/MongoDB.EntityFrameworkCore/Extensions/MongoServiceCollectionExtensions.cs:66 in AddMongoDB
Reproduction / trigger path
Analyzed trigger path from static analysis — not an executed PoC. Confirm with a concrete repro before handing off.
Attacker controls: None over triggering — the application's own connection string determines what leaks; a log reader passively harvests any secret placed outside the password field, or the full raw string from a logged parse exception.
- (source) src/MongoDB.EntityFrameworkCore/Extensions/MongoDbContextOptionsExtensions.cs:73 in UseMongoDB — Application's connection string (potentially carrying AWS_SESSION_TOKEN in authMechanismProperties, proxyPassword, or other query-option secrets) enters via WithConnectionString; sibling overload at line 118 and AddMongoDB wrappers funnel to the same path.
- (hop) src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:81 in WithConnectionString — Builds the 'loggable' copy of the connection string by calling the sanitizer.
- (hop) src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:269 in SanitizeConnectionStringForLogging — Redacts ONLY the password field; all other URL components including query-string secrets round-trip via MongoUrlBuilder.ToString(). Line 268 throws pre-redaction on malformed input, leaking the raw string in exception text.
- (sink) src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:324 in CreateLogFragment — Under-redacted string appended verbatim into LogFragment, which EF Core emits in its default Information-level 'context initialized ... with options:' log message.
Root cause
- src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:268-270 — the sanitizer parses the connection string with MongoUrlBuilder and replaces ONLY builder.Password with "redacted"; ToString() re-serializes username and all query-string options (authMechanismProperties incl. AWS_SESSION_TOKEN, proxyPassword) intact.
- src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:268 — a malformed connection string throws the driver's parse exception before any redaction, so the raw string (password included) escapes UseMongoDB inside the exception message.
- src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:322-324 — CreateLogFragment appends the under-redacted string verbatim into LogFragment, which EF Core writes to application logs in its default Information-level context-initialized event.
- tests/MongoDB.EntityFrameworkCore.SpecificationTests/Extensions/MongoDbContextOptionsExtensionsTest.cs:123-124 — the repo's own test proves username and query options round-trip into LogFragment.
Ownership
Assigned teams: @mongodb/dbx-csharp-dotnet
Filed from Aegis finding 8f9e94be224a (scan scan-6cd4cd27c8ab) · primitive: Password-only redaction round-trips every other connection-string secret into the default Information-level provider-options log message. · categories: Secret Leakage, Credential Exposure, Error Information Leak