Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-18905 | Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 18 Sep 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mongodb:mongodb:-:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Tue, 17 Sep 2024 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0 | Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2024-09-17T01:51:09.452Z
Reserved: 2021-05-05T00:00:00
Link: CVE-2021-32039
Updated: 2024-08-03T23:17:28.896Z
Status : Modified
Published: 2022-01-20T15:15:07.893
Modified: 2024-11-21T06:06:45.610
Link: CVE-2021-32039
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD