SCA: security update for org.mongodb:mongo-java-driver, org.mongodb:mongodb-driver, org.mongodb:mongodb-driver-legacy, org.mongodb:mongodb-driver-sync (GHSA-rghw-6px2-fgwc)

medium Tenable Self-Hosted Container Security Plugin ID 418728

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to
perform correct host name verification on the KMS server’s certificate. This vulnerability in combination
with a privileged network position active MITM attack could result in interception of traffic between the
Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered
during internal testing and affects all versions of the Java driver that support CSFLE. The Java async,
Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic
payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and
Azure network fabrics due to compensating controls in these environments. This issue does not impact
driver workloads that don’t use Field Level Encryption. (CVE-2021-20328)

See Also

https://github.com/advisories/GHSA-rghw-6px2-fgwc

Plugin Details

Severity: Medium

ID: 418728

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.04

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:A/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2021-20328

CVSS v3

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/24/2022

Vulnerability Publication Date: 2/25/2021

Reference Information

CVE: CVE-2021-20328

cwe: CWE-295