Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85cq-4fh4-j8cv

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 6.5

Описание

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.

EPSS

Процентиль: 21%
0.00287
Низкий

7 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.

CVSS3: 6.5
nvd
около 1 месяца назад

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.

CVSS3: 6.5
debian
около 1 месяца назад

An issue in MongoDB Server's applyOps command could allow an authentic ...

EPSS

Процентиль: 21%
0.00287
Низкий

7 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-863