Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77w4-3h74-q5hf

Опубликовано: 01 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

EPSS

Процентиль: 40%
0.0018
Низкий

3.1 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.1
ubuntu
около 1 года назад

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

CVSS3: 3.1
nvd
около 1 года назад

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

CVSS3: 3.1
debian
около 1 года назад

A user authorized to access a view may be able to alter the intended c ...

CVSS3: 3.1
fstec
около 1 года назад

Уязвимость системы управления базами данных MongoDB, связанная с ошибками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
redos
11 месяцев назад

Множественные уязвимости mongodb-org

EPSS

Процентиль: 40%
0.0018
Низкий

3.1 Low

CVSS3

Дефекты

CWE-284