Bug 1362580

Summary: mongodb: Logging potentially sensitive information when authenticating
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: abhgupta, admiller, anthomas, apevec, bhu, bkearney, bretm, cbillett, ccoleman, chris, chrisw, cvsbot-xmlrpc, databases-maint, dedgar, dmcphers, ehelms, ggainey, gmollett, hhorak, iboverma, jgoulding, jialiu, jmatthew, joelsmith, johan.o.hedin, jokerman, jorton, jross, jschluet, juwatts, katello-bugs, lhh, lmeyer, lpeer, markmc, mcressma, mhulan, mmccomas, mmccune, mrg-program-list, nmoumoul, ohadlevy, osousa, pcreech, rbryant, rchan, rhui-bugs, satellite6-bugs, sclewis, smallamp, srevivo, strobert, tdawson, tdecacqu, tiwillia, tlestach, tmalecek, tomckay, tsanders, williams
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: mongodb 2.5.4 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-21 00:54:23 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1362581, 1362583    
Bug Blocks: 1362585    

Description Adam Mariš 2016-08-02 14:46:53 UTC
It was found that potentially sensitive information were being logged when logging authentications.

Upstream bug:

https://jira.mongodb.org/browse/SERVER-9476

Upstream patch:

https://github.com/mongodb/mongo/commit/f85ceb17b37210eef71e8113162c41368bfd5c12

Comment 2 Adam Mariš 2016-08-02 14:48:38 UTC
Created mongodb tracking bugs for this issue:

Affects: epel-all [bug 1362583]

Comment 5 Fedora Update System 2016-09-06 03:49:43 UTC
mongodb-2.4.14-3.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.