Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-50605

Add {logMessage: "msg"} test-only command

    • Type: Icon: Improvement Improvement
    • Resolution: Fixed
    • Priority: Icon: Major - P3 Major - P3
    • 4.7.0, 4.4.2, 4.2.11, 3.6.21, 4.0.22
    • Affects Version/s: None
    • Component/s: None
    • None
    • Fully Compatible
    • v4.4, v4.2, v4.0, v3.6
    • Security 2020-09-07

      CVE ID: CVE-2021-20333

      Title: Server log entry spoofing via newline injection

      Description: Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split.

      CVSSv3: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

      CWE ID: CWE-117: Improper Output Neutralization for Logs

      Affected products: mongod and mongos servers

      Affected versions: 4.2.0-4.2.10, 4.0.0-4.0.21, 3.6.0-3.6.20

      Fixes available: 4.2.11+, 4.0.22+, 3.6.21+, as well as all releases from 4.4.0 onwards

      Discovery: Internally

            Assignee:
            sara.golemon@mongodb.com Sara Golemon
            Reporter:
            sara.golemon@mongodb.com Sara Golemon
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: