THREATOPS
THREAT OPSThreat News › [NVD] CVE-2021-20327 (MEDIUM 6.4) — A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Node

[NVD] CVE-2021-20327 (MEDIUM 6.4) — A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Node

lownvdPublished 2021-02-25

CVE-2021-20327 CVSS: 6.4 MEDIUM Published: 2021-02-25T17:15:28.160

A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Node.js driver and the KMS service rendering client-side

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-20327