<!-- 
RSS generated by JIRA (9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66) at Thu Feb 08 05:23:06 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>MongoDB Jira</title>
    <link>https://jira.mongodb.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.7.1</version>
        <build-number>970001</build-number>
        <build-date>13-04-2023</build-date>
    </build-info>


<item>
            <title>[SERVER-50605] Add {logMessage: &quot;msg&quot;} test-only command</title>
                <link>https://jira.mongodb.org/browse/SERVER-50605</link>
                <project id="10000" key="SERVER">Core Server</project>
                    <description>&lt;p&gt;&lt;b&gt;CVE ID:&lt;/b&gt;&#160;CVE-2021-20333&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Title:&lt;/b&gt;&#160;Server log entry spoofing via newline injection&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt; Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;CVSSv3:&lt;/b&gt; 5.3 &lt;a href=&quot;https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;b&gt;CWE ID:&lt;/b&gt; CWE-117: Improper Output Neutralization for Logs&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Affected products:&lt;/b&gt;&#160;mongod and mongos servers&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Affected versions:&lt;/b&gt;&#160;4.2.0-4.2.10, 4.0.0-4.0.21, 3.6.0-3.6.20&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Fixes available:&lt;/b&gt;&#160;4.2.11+, 4.0.22+, 3.6.21+, as well as all releases from 4.4.0 onwards&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Discovery:&lt;/b&gt;&#160;Internally&lt;/p&gt;</description>
                <environment></environment>
        <key id="1455752">SERVER-50605</key>
            <summary>Add {logMessage: &quot;msg&quot;} test-only command</summary>
                <type id="4" iconUrl="https://jira.mongodb.org/secure/viewavatar?size=xsmall&amp;avatarId=14710&amp;avatarType=issuetype">Improvement</type>
                                            <priority id="3" iconUrl="https://jira.mongodb.org/images/icons/priorities/major.svg">Major - P3</priority>
                        <status id="6" iconUrl="https://jira.mongodb.org/images/icons/statuses/closed.png" description="The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.">Closed</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="13201">Fixed</resolution>
                                        <assignee username="sara.golemon@mongodb.com">Sara Golemon</assignee>
                                    <reporter username="sara.golemon@mongodb.com">Sara Golemon</reporter>
                        <labels>
                    </labels>
                <created>Fri, 28 Aug 2020 14:51:15 +0000</created>
                <updated>Sun, 29 Oct 2023 22:03:53 +0000</updated>
                            <resolved>Tue, 1 Sep 2020 17:04:36 +0000</resolved>
                                                    <fixVersion>4.7.0</fixVersion>
                    <fixVersion>4.4.2</fixVersion>
                    <fixVersion>4.2.11</fixVersion>
                    <fixVersion>3.6.21</fixVersion>
                    <fixVersion>4.0.22</fixVersion>
                                                        <votes>0</votes>
                                    <watches>2</watches>
                                                                                                                <comments>
                            <comment id="3459576" author="xgen-internal-githook" created="Thu, 22 Oct 2020 17:06:24 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;Sara Golemon&apos;, &apos;email&apos;: &apos;sara.golemon@mongodb.com&apos;, &apos;username&apos;: &apos;sgolemon&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-50605&quot; title=&quot;Add {logMessage: &amp;quot;msg&amp;quot;} test-only command&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-50605&quot;&gt;&lt;del&gt;SERVER-50605&lt;/del&gt;&lt;/a&gt; Add logMessage test-only command&lt;/p&gt;

&lt;p&gt;(cherry picked from commit cbdf4deaa4ef4352750893ab0b4b276b86e3026f)&lt;br/&gt;
Branch: v3.6&lt;br/&gt;
&lt;a href=&quot;https://github.com/mongodb/mongo/commit/cd8cce6dcb3d63bbf4bf882379540ed8b719dfc4&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/mongodb/mongo/commit/cd8cce6dcb3d63bbf4bf882379540ed8b719dfc4&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="3457812" author="xgen-internal-githook" created="Thu, 22 Oct 2020 01:45:28 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;Sara Golemon&apos;, &apos;email&apos;: &apos;sara.golemon@mongodb.com&apos;, &apos;username&apos;: &apos;sgolemon&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-50605&quot; title=&quot;Add {logMessage: &amp;quot;msg&amp;quot;} test-only command&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-50605&quot;&gt;&lt;del&gt;SERVER-50605&lt;/del&gt;&lt;/a&gt; Add logMessage test-only command&lt;/p&gt;

&lt;p&gt;(cherry picked from commit cbdf4deaa4ef4352750893ab0b4b276b86e3026f)&lt;br/&gt;
Branch: v4.0&lt;br/&gt;
&lt;a href=&quot;https://github.com/mongodb/mongo/commit/40327aeff1f3f76cba2884893eb322f0449b1928&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/mongodb/mongo/commit/40327aeff1f3f76cba2884893eb322f0449b1928&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="3456914" author="xgen-internal-githook" created="Wed, 21 Oct 2020 17:27:12 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;Sara Golemon&apos;, &apos;email&apos;: &apos;sara.golemon@mongodb.com&apos;, &apos;username&apos;: &apos;sgolemon&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-50605&quot; title=&quot;Add {logMessage: &amp;quot;msg&amp;quot;} test-only command&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-50605&quot;&gt;&lt;del&gt;SERVER-50605&lt;/del&gt;&lt;/a&gt; Add logMessage test-only command&lt;/p&gt;

&lt;p&gt;Based on:&lt;br/&gt;
(cherry picked from commit 273cba82968bab5316b5f937875757a12f363626)&lt;/p&gt;

&lt;p&gt;Refactored to accomodate logv1&lt;br/&gt;
Branch: v4.2&lt;br/&gt;
&lt;a href=&quot;https://github.com/mongodb/mongo/commit/78a269596edf46413b8533132d10da995953d5ee&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/mongodb/mongo/commit/78a269596edf46413b8533132d10da995953d5ee&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="3400050" author="xgen-internal-githook" created="Thu, 17 Sep 2020 21:48:44 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;Sara Golemon&apos;, &apos;email&apos;: &apos;sara.golemon@mongodb.com&apos;, &apos;username&apos;: &apos;sgolemon&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-50605&quot; title=&quot;Add {logMessage: &amp;quot;msg&amp;quot;} test-only command&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-50605&quot;&gt;&lt;del&gt;SERVER-50605&lt;/del&gt;&lt;/a&gt; Add logMessage test-only command&lt;br/&gt;
Branch: v4.4&lt;br/&gt;
&lt;a href=&quot;https://github.com/mongodb/mongo/commit/001aed0981a442f8cccc091f330e31e3f22dfde3&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/mongodb/mongo/commit/001aed0981a442f8cccc091f330e31e3f22dfde3&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="3400049" author="xgen-internal-githook" created="Thu, 17 Sep 2020 21:48:38 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;Sara Golemon&apos;, &apos;email&apos;: &apos;sara.golemon@mongodb.com&apos;, &apos;username&apos;: &apos;sgolemon&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-50605&quot; title=&quot;Add {logMessage: &amp;quot;msg&amp;quot;} test-only command&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-50605&quot;&gt;&lt;del&gt;SERVER-50605&lt;/del&gt;&lt;/a&gt; Validate escaping of audit applicationMessage&lt;br/&gt;
Branch: v4.4&lt;br/&gt;
&lt;a href=&quot;https://github.com/10gen/mongo-enterprise-modules/commit/391ea3c8618b58826a93440a9bf46d78275183ca&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/10gen/mongo-enterprise-modules/commit/391ea3c8618b58826a93440a9bf46d78275183ca&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="3370450" author="xgen-internal-githook" created="Tue, 1 Sep 2020 16:07:45 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;Sara Golemon&apos;, &apos;email&apos;: &apos;sara.golemon@mongodb.com&apos;, &apos;username&apos;: &apos;sgolemon&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-50605&quot; title=&quot;Add {logMessage: &amp;quot;msg&amp;quot;} test-only command&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-50605&quot;&gt;&lt;del&gt;SERVER-50605&lt;/del&gt;&lt;/a&gt; Add logMessage test-only command&lt;br/&gt;
Branch: master&lt;br/&gt;
&lt;a href=&quot;https://github.com/mongodb/mongo/commit/3f70a7ed1c4a8c30bcd2f7d30adfe3e018fc13a8&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/mongodb/mongo/commit/3f70a7ed1c4a8c30bcd2f7d30adfe3e018fc13a8&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="3370449" author="xgen-internal-githook" created="Tue, 1 Sep 2020 16:07:38 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;Sara Golemon&apos;, &apos;email&apos;: &apos;sara.golemon@mongodb.com&apos;, &apos;username&apos;: &apos;sgolemon&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-50605&quot; title=&quot;Add {logMessage: &amp;quot;msg&amp;quot;} test-only command&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-50605&quot;&gt;&lt;del&gt;SERVER-50605&lt;/del&gt;&lt;/a&gt; Validate escaping of audit applicationMessage&lt;br/&gt;
Branch: master&lt;br/&gt;
&lt;a href=&quot;https://github.com/10gen/mongo-enterprise-modules/commit/db499d40b1e8ca8260176a867346f015c6bec9a5&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/10gen/mongo-enterprise-modules/commit/db499d40b1e8ca8260176a867346f015c6bec9a5&lt;/a&gt;&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10420">
                    <name>Backports</name>
                                            <outwardlinks description="backported by">
                                                        </outwardlinks>
                                                        </issuelinktype>
                            <issuelinktype id="10012">
                    <name>Related</name>
                                                                <inwardlinks description="is related to">
                                                        </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                <customfield id="customfield_10050" key="com.atlassian.jira.toolkit:comments">
                        <customfieldname># Replies</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>7.0</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_18555" key="com.onresolve.jira.groovy.groovyrunner:scripted-field">
                        <customfieldname># of Sprints</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1.0</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_12450" key="com.atlassian.jira.plugin.system.customfieldtypes:multicheckboxes">
                        <customfieldname>Backport Requested</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="18953"><![CDATA[v4.4]]></customfieldvalue>
    <customfieldvalue key="16775"><![CDATA[v4.2]]></customfieldvalue>
    <customfieldvalue key="15640"><![CDATA[v4.0]]></customfieldvalue>
    <customfieldvalue key="15141"><![CDATA[v3.6]]></customfieldvalue>
    
                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10011" key="com.atlassian.jira.plugin.system.customfieldtypes:radiobuttons">
                        <customfieldname>Backwards Compatibility</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10038"><![CDATA[Fully Compatible]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                            <customfield id="customfield_10055" key="com.atlassian.jira.ext.charting:firstresponsedate">
                        <customfieldname>Date of 1st Reply</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>Tue, 1 Sep 2020 16:07:38 +0000</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10052" key="com.atlassian.jira.toolkit:dayslastcommented">
                        <customfieldname>Days since reply</customfieldname>
                        <customfieldvalues>
                                        3 years, 15 weeks, 6 days ago
    
                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_18254" key="com.onresolve.jira.groovy.groovyrunner:scripted-field">
                        <customfieldname>Dependencies</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[]]></customfieldvalue>


                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_15850" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_17050" key="com.atlassian.jira.plugin.system.customfieldtypes:radiobuttons">
                        <customfieldname>Downstream Team Attention</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="16941"><![CDATA[Not Needed]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    <customfield id="customfield_10057" key="com.atlassian.jira.toolkit:lastusercommented">
                        <customfieldname>Last comment by Customer</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>true</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10056" key="com.atlassian.jira.toolkit:lastupdaterorcommenter">
                        <customfieldname>Last commenter</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>luke.bonanomi@mongodb.com</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_11151" key="com.atlassian.jira.toolkit:LastCommentDate">
                        <customfieldname>Last public comment date</customfieldname>
                        <customfieldvalues>
                            3 years, 15 weeks, 6 days ago
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                    <customfield id="customfield_10051" key="com.atlassian.jira.toolkit:participants">
                        <customfieldname>Participants</customfieldname>
                        <customfieldvalues>
                                        <customfieldvalue>xgen-internal-githook</customfieldvalue>
            <customfieldvalue>sara.golemon@mongodb.com</customfieldvalue>
    
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                        <customfield id="customfield_14254" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Product Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hy2plz:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                <customfield id="customfield_12550" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>2|hxp9pz:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10558" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_23361" key="com.onresolve.jira.groovy.groovyrunner:scripted-field">
                        <customfieldname>Requested By</customfieldname>
                        <customfieldvalues>
                                

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                        <customfield id="customfield_10557" key="com.pyxis.greenhopper.jira:gh-sprint">
                        <customfieldname>Sprint</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue id="4145">Security 2020-09-07</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                            <customfield id="customfield_10053" key="com.atlassian.jira.ext.charting:timeinstatus">
                        <customfieldname>Time In Status</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_22870" key="com.onresolve.jira.groovy.groovyrunner:scripted-field">
                        <customfieldname>Triagers</customfieldname>
                        <customfieldvalues>
                                

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                    <customfield id="customfield_14350" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>serverRank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hy2bvb:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                    </customfields>
    </item>
</channel>
</rss>