From 373c4df57e12d7339f8a786a5a0a0a08ff1c3861 Mon Sep 17 00:00:00 2001 From: Moritz Muehlenhoff Date: Mon, 4 Sep 2023 12:58:04 +0200 Subject: "new" issues in mongodb drivers --- data/CVE/list | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) (limited to 'data') diff --git a/data/CVE/list b/data/CVE/list index 889f337771..ab76ca5bae 100644 --- a/data/CVE/list +++ b/data/CVE/list @@ -164733,7 +164733,20 @@ CVE-2021-32052 (In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3 CVE-2021-32051 (Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via ...) NOT-FOR-US: Hexagon G!nius Auskunftsportal CVE-2021-32050 (Some MongoDB Drivers may erroneously publish events containing authent ...) - TODO: check + - php-mongodb 1.11.1+1.9.2+1.7.5-4 + [bullseye] - php-mongodb (Minor issue) + - mongo-c-driver 1.18.0-1 + [bullseye] - mongo-c-driver (Minor issue) + - node-mongodb + [bookworm] - node-mongodb (Minor issue) + [bullseye] - node-mongodb (Minor issue) + NOTE: https://jira.mongodb.org/browse/PHPC-1869 + NOTE: https://github.com/mongodb/mongo-php-driver/pull/1235 + NOTE: https://jira.mongodb.org/browse/NODE-3356 + NOTE: https://github.com/mongodb/node-mongodb-native/commit/8c8b4c3b8c55f10fb96f63d3bbfa5d408b4ed7d0 + NOTE: https://github.com/mongodb/node-mongodb-native/commit/b98f2061de9e8b0a814e3e7d39a0e914245953d0 + NOTE: https://jira.mongodb.org/browse/CDRIVER-3797 + NOTE: https://github.com/mongodb/mongo-c-driver/commit/6d8fc7eaadea8a0dab163e88b91244af12e0c97a (1.18.0) CVE-2021-32049 RESERVED CVE-2021-32048 -- cgit v1.2.3