Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0
References
| Link | Resource |
|---|---|
| https://github.com/mongodb-js/vscode/releases/tag/v0.8.0 | Release Notes Third Party Advisory |
| https://jira.mongodb.org/browse/VSCODE-313 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2022-01-20 07:15
Updated : 2022-01-26 11:53
NVD link : CVE-2021-32039
Mitre link : CVE-2021-32039
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
mongodb
- mongodb


