ExportXMLWordPrintableJSON

    • None
    • 0.5
    • Dotnet Drivers
    • Not Needed
    • None
    • None
    • None
    • None
    • None
    • None

      Summary

      Secrets placed in connection-string options, such as AWS session tokens or proxy passwords, are written unredacted to application logs; only the password field is masked.

      Impact

      Database, cloud (AWS), and proxy credential material is persisted to application logs where lower-trust log readers and downstream log pipelines can recover it and authenticate as the application.
      Severity: high (upper bound critical)
      Exploitability: exploitable — Deterministic — every context initialization emits the unredacted fragment to logs by default; exploitation is simply reading the logs, with the attacker controlling nothing.
      Customer data: credentials, tokens, secrets (logs)

      Location

      • src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:269 in SanitizeConnectionStringForLogging
      • src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:324 in CreateLogFragment
      • src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:268 in SanitizeConnectionStringForLogging
      • src/MongoDB.EntityFrameworkCore/Extensions/MongoDbContextOptionsExtensions.cs:73 in UseMongoDB
      • src/MongoDB.EntityFrameworkCore/Extensions/MongoDbContextOptionsExtensions.cs:118 in UseMongoDB
      • src/MongoDB.EntityFrameworkCore/Extensions/MongoServiceCollectionExtensions.cs:66 in AddMongoDB

      Reproduction / trigger path

      Analyzed trigger path from static analysis — not an executed PoC. Confirm with a concrete repro before handing off.

      Attacker controls: None over triggering — the application's own connection string determines what leaks; a log reader passively harvests any secret placed outside the password field, or the full raw string from a logged parse exception.

      1. (source) src/MongoDB.EntityFrameworkCore/Extensions/MongoDbContextOptionsExtensions.cs:73 in UseMongoDB — Application's connection string (potentially carrying AWS_SESSION_TOKEN in authMechanismProperties, proxyPassword, or other query-option secrets) enters via WithConnectionString; sibling overload at line 118 and AddMongoDB wrappers funnel to the same path.
      2. (hop) src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:81 in WithConnectionString — Builds the 'loggable' copy of the connection string by calling the sanitizer.
      3. (hop) src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:269 in SanitizeConnectionStringForLogging — Redacts ONLY the password field; all other URL components including query-string secrets round-trip via MongoUrlBuilder.ToString(). Line 268 throws pre-redaction on malformed input, leaking the raw string in exception text.
      4. (sink) src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:324 in CreateLogFragment — Under-redacted string appended verbatim into LogFragment, which EF Core emits in its default Information-level 'context initialized ... with options:' log message.

      Root cause

      • src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:268-270 — the sanitizer parses the connection string with MongoUrlBuilder and replaces ONLY builder.Password with "redacted"; ToString() re-serializes username and all query-string options (authMechanismProperties incl. AWS_SESSION_TOKEN, proxyPassword) intact.
      • src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:268 — a malformed connection string throws the driver's parse exception before any redaction, so the raw string (password included) escapes UseMongoDB inside the exception message.
      • src/MongoDB.EntityFrameworkCore/Infrastructure/MongoOptionsExtension.cs:322-324 — CreateLogFragment appends the under-redacted string verbatim into LogFragment, which EF Core writes to application logs in its default Information-level context-initialized event.
      • tests/MongoDB.EntityFrameworkCore.SpecificationTests/Extensions/MongoDbContextOptionsExtensionsTest.cs:123-124 — the repo's own test proves username and query options round-trip into LogFragment.

      Ownership

      Assigned teams: @mongodb/dbx-csharp-dotnet


      Filed from Aegis finding 8f9e94be224a (scan scan-6cd4cd27c8ab) · primitive: Password-only redaction round-trips every other connection-string secret into the default Information-level provider-options log message. · categories: Secret Leakage, Credential Exposure, Error Information Leak

      https://docs.google.com/document/d/1osPjSiI-pvMXtrI49QVqwrIK21_nU38fsp7tJlQpDlY/edit?tab=t.0#heading=h.biijq6ke6z0p

            Assignee:
            Damien Guard
            Reporter:
            Boris Dogadov
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: