Vulnerabilities (CVE)

Filtered by vendor Mongodb
Filtered by product Java Driver
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20328 2 Mongodb, Quarkus 2 Java Driver, Quarkus 2024-11-21 4.3 MEDIUM 6.4 MEDIUM
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CS ...

Show More