[CSHARP-3521] Security sensitive commands are not redacted in command started events Created: 01/Apr/21  Updated: 28/Oct/23  Resolved: 06/Apr/21

Status: Closed
Project: C# Driver
Component/s: Diagnostics
Affects Version/s: 2.11.0, 2.12.0
Fix Version/s: 2.12.2

Type: Bug Priority: Major - P3
Reporter: Jeffrey Yemin Assignee: Robert Stam
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Related
Backwards Compatibility: Minor Change

 Description   

The commit for CSHARP-3032 introduced an undetected regression to security-sensitive command redaction when sending command started events. As a result, the following commands are no longer redacted:

  • isMaster (with speculativeAuthenticate)
  • saslStart
  • saslContinue
  • createUser
  • updateUser


 Comments   
Comment by Githook User [ 06/Apr/21 ]

Author:

{'name': 'rstam', 'email': 'robert@robertstam.org', 'username': 'rstam'}

Message: CSHARP-3521: Redact security sensitive commands and replies.
Branch: v2.12.x
https://github.com/mongodb/mongo-csharp-driver/commit/1f1a526e93ed7aa254759704b19f5ee66a3af365

Comment by Githook User [ 06/Apr/21 ]

Author:

{'name': 'rstam', 'email': 'robert@robertstam.org', 'username': 'rstam'}

Message: CSHARP-3521: Redact security sensitive commands and replies.
Branch: master
https://github.com/mongodb/mongo-csharp-driver/commit/97fe954c36d45c152e3b8db0f87ecf0912a2569a

Generated at Wed Feb 07 21:45:31 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.