Описание
In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.0.0 (включая) до 5.0.22 (исключая)Версия от 6.0.0 (включая) до 6.0.17 (исключая)
Одно из
cpe:2.3:a:mongodb:ops_manager_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:ops_manager_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 33%
0.00135
Низкий
7.2 High
CVSS3
Дефекты
CWE-648
CWE-269
Связанные уязвимости
CVSS3: 7.2
github
больше 2 лет назад
In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.
EPSS
Процентиль: 33%
0.00135
Низкий
7.2 High
CVSS3
Дефекты
CWE-648
CWE-269