[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-2389 -- mongodb

ID: oval:org.secpod.oval:def:2005279Date: (C)2020-10-22   (M)2024-01-29
Class: VULNERABILITYFamily: unix




Incorrect scoping of kill operations in MongoDB Server"s packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.11; v3.6 versions prior to 3.6.14; v3.4 versions prior to 3.4.22.

Platform:
Debian 9.x
Product:
mongodb
Reference:
CVE-2019-2389
CVE    1
CVE-2019-2389
CPE    2
cpe:/a:mongodb:mongodb
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies