mongodb.libmongocrypt is vulnerable to Improper Input Validation
44
Medium Risk
libmongocrypt builds MongoDB namespace strings from database and collection name arguments without validating their contents. When these identifiers carry externally influenced input, an embedded . in a database name can retarget an operation to a different namespace, and an embedded NUL byte can truncate a BSON collection or namespace name and cause inconsistent encryption and schema processing. These unchecked names let client-side encrypted operations be redirected across databases or collections. The fix rejects database and collection name arguments containing a . or a NUL byte.
You are affected if you are using a version that falls within the vulnerable range and you pass externally influenced or untrusted database or collection names into libmongocrypt APIs.
mongodb.libmongocrypt is vulnerable to Improper Input Validation in versions 0.0.1 - 1.20.2.
Upgrade the mongodb.libmongocrypt library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.