pymongo is vulnerable to Insertion of Sensitive Information into Log File
25
Low Risk
Affected versions of the package may expose sensitive information in log files because invalid documents are included directly in bson.errors.InvalidDocument error messages. This behavior can leak user-provided or sensitive data when errors are logged, rather than safely storing the invalid document separately on the exception object.
You are affected if you are using a version that falls within the vulnerable range.
pymongo is vulnerable to Insertion of Sensitive Information into Log File in versions 4.11 - 4.15.5.
Upgrade the pymongo library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant