Логотип exploitDog
bind:CVE-2025-6713
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-6713

Количество 4

Количество 4

ubuntu логотип

CVE-2025-6713

около 1 месяца назад

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2025-6713

около 1 месяца назад

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2025-6713

около 1 месяца назад

An unauthorized user may leverage a specially crafted aggregation pipe ...

CVSS3: 7.7
EPSS: Низкий
github логотип

GHSA-p3jv-2cpc-349v

около 1 месяца назад

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.20 and MongoDB Server v6.0 versions prior to 6.0.22

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-6713

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22

CVSS3: 7.7
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-6713

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22

CVSS3: 7.7
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-6713

An unauthorized user may leverage a specially crafted aggregation pipe ...

CVSS3: 7.7
0%
Низкий
около 1 месяца назад
github логотип
GHSA-p3jv-2cpc-349v

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.20 and MongoDB Server v6.0 versions prior to 6.0.22

CVSS3: 7.7
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу