CyberRota Analysis
AI-GeneratedThe MongoDB Connector for BI is vulnerable due to a flaw in the mongodrdl component that can expose a TLS private-key password via standard error when provided through both the connection URI and command-line options. This could allow a local user with access to the command output and the encrypted key file to retrieve the password and potentially compromise the associated TLS client key. Organizations using MongoDB Connector for BI should prioritize addressing this vulnerability to mitigate the risk of unauthorized access to sensitive data.
Original NVD Description
In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access the associated TLS client key.