Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-13067

Опубликовано: 22 июл. 2026
Источник: debian
EPSS Низкий

Описание

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongodbremovedpackage

Примечания

  • https://jira.mongodb.org/browse/SERVER-128387

EPSS

Процентиль: 0%
0.00067
Низкий

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 1 месяца назад

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.

CVSS3: 6.3
nvd
около 1 месяца назад

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.

CVSS3: 6.3
github
около 1 месяца назад

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected scenarios require local access to the proxy Unix domain socket and a valid X.509 certificate issued by a trusted certificate authority.

EPSS

Процентиль: 0%
0.00067
Низкий
Уязвимость CVE-2026-13067