5.7
CVE-2026-92758
- EPSS 0.11%
- Veröffentlicht 17.09.2026 19:16:13
- Zuletzt bearbeitet 24.09.2026 15:34:25
- Erkennungen
Logs may collect sensitive information
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MongoDB ≫ Entity Framework Core Provider SwPlatform .net Version >= 8.0.0 < 8.4.4
MongoDB ≫ Entity Framework Core Provider SwPlatform .net Version >= 9.0.0 < 9.1.4
MongoDB ≫ Entity Framework Core Provider SwPlatform .net Version >= 10.0.0 < 10.0.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.012 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MongoDb | 5.7 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| MongoDb | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
https://jira.mongodb.org/browse/EF-384