Specific cstrings input may not be properly validated in the Go Driver
CVE-2021-20329
6.8MEDIUM
What is CVE-2021-20329?
Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields into marshalled documents. This issue affects all MongoDB GO Drivers prior to and including 1.5.0.
Affected Version(s)
MongoDB Go Driver 1.0 <= 1.5.0