CVE-2021-20327 affects version 1.2.0 of the Node.js mongodb-client-encryption module, where it fails to properly validate KMS server certificates. This medium-severity vulnerability (CVSS 6.8) requires a privileged network position and an active Man-in-the-Middle (MITM) attack to intercept traffic, potentially compromising client-side field level encryption (CSFLE) effectiveness. While it does not impact applications within AWS, GCP, or Azure network fabrics due to existing controls, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.0CPE matchmatch criteria | cpe:2.3:a:mongodb:libmongocrypt:1.2.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.