Mongodb Connection String

Description

The source code repository contains sensitive information: MongoDB Connection String

Weakness:

009 - Sensitive information in source code

Category: Information Collection

Detection Strategy

    Matches MongoDB Connection String patterns in source code and configuration files

Vulnerable code example

MONGO_URL=mongodb://admin:[email protected]:27017/mydb
const uri = "mongodb+srv://dbuser:MyP%[email protected]/app?retryWrites=true"
mongodb://root:[email protected]:27017,10.0.0.2:27017/prod