[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Collapse of data into unsafe value vulnerability in MongoDB - CVE-2020-7921

ID: oval:org.secpod.oval:def:63839Date: (C)2020-06-16   (M)2024-01-29
Class: VULNERABILITYFamily: windows




The host is installed with MongoDB 4.2 before 4.2.3, 4.0 before 4.0.15 or 3.6 before 3.6.18 and is prone to a collapse of data into unsafe value vulnerability. A flaw is present in the application which fails to handle IP whitelisting protection mechanisms. Successful exploitation allows a user with valid credentials to bypass IP whitelisting protection mechanisms and perform administrative action.

Platform:
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 8.1
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012
Microsoft Windows 7
Microsoft Windows 10
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Product:
MongoDB
Reference:
CVE-2020-7921
CVE    1
CVE-2020-7921

© SecPod Technologies