Junglewise Threat Intelligence

GO-2021-0111 - Due to improper input sanitization when marshalling Go objects into BSON, a maliciously constructed Go structure could allow an attacker to

Severity: info · Published 2021-07-28

Technologies: go.mongodb.org/mongo-driver (Go). Vendors: Go.

Executive brief

Due to improper input sanitization when marshalling Go objects into BSON, a maliciously constructed Go structure could allow an attacker to inject additional fields into a MongoDB document. Users are affected if they use this package to handle untrusted user input.

Affected products

  • Go go.mongodb.org/mongo-driver

Related threats