Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-7882

Опубликовано: 29 сент. 2015
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

An authentication issue was found in MongoDB. The improper handling of LDAP authentication in MongoDB Enterprise versions 3.0.0 through 3.0.6 can allow an unauthenticated client to gain unauthorized access. The MongoDB Community Edition is not affected by this vulnerability.

Отчет

All versions of the following products which include mongodb include only MongoDB's Community edition, and are therefore not affected by this vulnerability:

  • Red Hat OpenStack Platform
  • Red Hat Software Collections
  • Red Hat Update Infrastructure

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)mongodbNot affected
Red Hat OpenStack Platform 10 (Newton)mongodbNot affected
Red Hat OpenStack Platform 9 (Mitaka)mongodbNot affected
Red Hat Satellite 6mongodbNot affected
Red Hat Software Collectionsrh-mongodb34-mongodbNot affected
Red Hat Software Collectionsrh-mongodb36-mongodbNot affected
Red Hat Update Infrastructure 3 for Cloud ProvidersmongodbNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1732358mongodb: improper handling of LDAP authentication leading to unauthorized access

EPSS

Процентиль: 74%
0.00805
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 6 лет назад

Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

CVSS3: 8.1
nvd
больше 6 лет назад

Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

CVSS3: 8.1
debian
больше 6 лет назад

Improper handling of LDAP authentication in MongoDB Server versions 3. ...

CVSS3: 8.1
github
больше 3 лет назад

Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

EPSS

Процентиль: 74%
0.00805
Низкий

9.1 Critical

CVSS3