Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77w4-3h74-q5hf

Опубликовано: 01 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

EPSS

Процентиль: 10%
0.00037
Низкий

3.1 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.1
ubuntu
3 месяца назад

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

CVSS3: 3.1
nvd
3 месяца назад

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

CVSS3: 3.1
debian
3 месяца назад

A user authorized to access a view may be able to alter the intended c ...

CVSS3: 3.1
fstec
3 месяца назад

Уязвимость системы управления базами данных MongoDB, связанная с ошибками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
redos
около 2 месяцев назад

Множественные уязвимости mongodb-org

EPSS

Процентиль: 10%
0.00037
Низкий

3.1 Low

CVSS3

Дефекты

CWE-284