Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities HKCERT

MongoDB Multiple Vulnerabilities

Multiple critical vulnerabilities in MongoDB, including remote code execution, denial of service, and privilege escalation, can be exploited by a remote attacker. Affected versions are MongoDB Driver 4.11.0 prior to 5.9.2, MongoDB Server 7.0.0 prior to 7.0.40, MongoDB Server 8.0.0 prior to 8.0.29, and MongoDB Server 8.3.0 prior to 8.3.8. The vendor has released fixes; administrators must apply the patches available via the MongoDB security alerts page.
Read Full Article →

Multiple vulnerabilities were identified in MongoDB. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, remote code execution, data manipulation, denial of service condition, elevation of privilege and sensitive information disclosure on the targeted system. Impact Denial of Service Information Disclosure Remote Code Execution Security Restriction Bypass Elevation of Privilege Data Manipulation System / Technologies affected MongoDB Driver 4.11.0 versions prior to 5.9.2 MongoDB Server 7.0.0 versions prior to 7.0.40 MongoDB Server 8.0.0 versions prior to 8.0.29 MongoDB Server 8.3.0 versions prior to 8.3.8 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://www.mongodb.com/resources/products/alerts#security

Share this article