Mongodb Ops Manager是美国Mongodb公司的一套支持管理、监视和备份MongoDB部署的解决方案。 MongoDB Ops Manager 存在安全漏洞,该漏洞源于特殊设计的API调用可能允许持有组织所有者特权的经过身份验证的用户获得具有全局角色特权的API密钥。以下产品及版本受到影响:MongoDB Ops Manager v4.2版本4.2.0-4.2.17、v4.3版本4.3.0-4.3.9和v4.4版本4.4.0-4.4.2。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MongoDB Inc. | MongoDB Ops Manager | 4.2 ~ 4.2.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-7925 | 7.5 HIGH | Denial of Service when processing malformed Role names |
| CVE-2018-20802 | 6.5 MEDIUM | Post-auth queries on compound index may crash mongod |
| CVE-2018-20803 | 6.5 MEDIUM | Infinite loop in aggregation expression |
| CVE-2018-20804 | 6.5 MEDIUM | Invariant failure in applyOps |
| CVE-2018-20805 | 6.5 MEDIUM | Invariant with $elemMatch |
| CVE-2019-20923 | 6.5 MEDIUM | Crash while handling internal Javascript exception types |
| CVE-2019-20924 | 6.5 MEDIUM | Invariant in IndexBoundsBuilder |
| CVE-2019-2392 | 6.5 MEDIUM | $mod can result in undefined behavior |
| CVE-2019-2393 | 6.5 MEDIUM | Crash while joining collections with $lookup |
| CVE-2020-7926 | 6.5 MEDIUM | Specific query can cause a DoS against MongoDB Server |
| CVE-2020-7928 | 6.5 MEDIUM | Improper neutralization of null byte leads to read overrun |
No comments yet