Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-10898

Passwords should be canonicalized according to unicode canonicalization NFC

    XMLWordPrintableJSON

Details

    • Icon: Improvement Improvement
    • Resolution: Done
    • Icon: Major - P3 Major - P3
    • None
    • None
    • Security
    • None
    • Server Security

    Description

      Similar to SERVER-10897, if drivers and the server don't engage in some canonicalization process for passwords, there is a strong risk for mismatches when the input device used by the end user produces a different encoding of a multi-code-point character, or a character that has multiple code point representations (a.k.a, greek capital omega and the Ohm symbol).

      Attachments

        Activity

          People

            backlog-server-security Backlog - Security Team
            schwerin@mongodb.com Andy Schwerin
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: