[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256148

 
 

909

 
 

199106

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-2386 -- mongodb

ID: oval:org.secpod.oval:def:2005280Date: (C)2020-10-22   (M)2024-01-29
Class: VULNERABILITYFamily: unix




After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user"s session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.9; v3.6 versions prior to 3.6.13; v3.4 versions prior to 3.4.22.

Platform:
Debian 9.x
Product:
mongodb
Reference:
CVE-2019-2386
CVE    1
CVE-2019-2386
CPE    2
cpe:/a:mongodb:mongodb
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies