Vulnerabilities (CVE)

Filtered by vendor Mongodb
Filtered by product Libmongocrypt
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-20327 1 Mongodb 1 Libmongocrypt 2024-11-21 4.3 MEDIUM 6.4 MEDIUM
A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Node.js driver and the KMS service rendering client-side field level encryption (CSFLE) ineffective. This issue was discovered during internal testing and affects mongodb-client-encryption module version 1.2.0, which was ava ...

Show More