CVE-2025-6711Log File Information Exposure in INC Mongodb Server

Severity
4.9MEDIUMNVD
CNA4.4
EPSS
0.1%
top 76.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 7

Description

An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects MongoDB Server v8.0 versions prior to 8.0.5, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server v6.0 versions prior to 6.0.21.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5mongodb_inc/mongodb_server6.06.0.21+2
NVDmongodb/mongodb6.0.06.0.21+2

🔴Vulnerability Details

3
OSV
CVE-2025-6711: An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are enco2025-07-07
CVEList
Incomplete Redaction of Sensitive Information in MongoDB Server Logs2025-07-07
GHSA
GHSA-2844-pfq3-9x4m: An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are enco2025-07-07
CVE-2025-6711 — Log File Information Exposure | cvebase