Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77w4-3h74-q5hf

Опубликовано: 01 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

EPSS

Процентиль: 4%
0.00022
Низкий

3.1 Low

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 3.1
ubuntu
5 месяцев назад

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

CVSS3: 3.1
nvd
5 месяцев назад

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

CVSS3: 3.1
debian
5 месяцев назад

A user authorized to access a view may be able to alter the intended c ...

CVSS3: 3.1
fstec
5 месяцев назад

Уязвимость системы управления базами данных MongoDB, связанная с ошибками разграничения доступа, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 8.1
redos
4 месяца назад

Множественные уязвимости mongodb-org

EPSS

Процентиль: 4%
0.00022
Низкий

3.1 Low

CVSS3

Дефекты

CWE-284