Description
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2
CVSS Metrics
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
- Attack Vector
- network
- Complexity
- low
- Privileges
- low
- User Action
- none
- Scope
- changed
- Confidentiality
- none
- Integrity
- low
- Availability
- low
- Weaknesses
- CWE-228
Metadata
- Primary Vendor
- MONGODB
- Published
- 7/2/2024
- Last Modified
- 10/2/2025
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
mongodb : rust_driver
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.