CVE-2021-20328 is a medium-severity vulnerability affecting specific versions of the MongoDB Java driver that support client-side field level encryption (CSFLE). The flaw lies in the driver's failure to properly verify the hostname on the Key Management Service (KMS) server's certificate. This misconfiguration, when combined with a privileged network position and an active Man-in-the-Middle (MITM) attack, could allow an attacker to intercept traffic between the Java driver and the KMS, effectively rendering Field Level Encryption useless. While the CVSS score is 6.8 (Medium), its attack vector is adjacent and attack complexity is high, meaning an attacker needs to be on the same local network and have specialized knowledge to exploit it. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.11.0, < 3.11.3CPE matchmatch criteria | cpe:2.3:a:mongodb:java_driver:*:*:*:*:*:mongodb:*:* | ||
>= 3.12.0, < 3.12.8CPE matchmatch criteria | cpe:2.3:a:mongodb:java_driver:*:*:*:*:*:mongodb:*:* | ||
>= 4.0.0, < 4.0.6CPE matchmatch criteria | cpe:2.3:a:mongodb:java_driver:*:*:*:*:*:mongodb:*:* | ||
>= 4.1.0, < 4.1.2CPE matchmatch criteria | cpe:2.3:a:mongodb:java_driver:*:*:*:*:*:mongodb:*:* | ||
>= 4.2.0, < 4.2.1CPE matchmatch criteria | cpe:2.3:a:mongodb:java_driver:*:*:*:*:*:mongodb:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.