CVE-2023-4009
Summary
| CVE | CVE-2023-4009 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-08 09:15:00 UTC |
| Updated | 2023-08-31 19:15:00 UTC |
| Description | In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mongodb | Ops Manager Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Ops Manager Server Changelog — MongoDB Ops Manager 5.0 | MISC | www.mongodb.com | |
| Ops Manager Server Changelog — MongoDB Ops Manager 6.0 | MISC | www.mongodb.com | |
| CVE-2023-4009 MongoDB Vulnerability in NetApp Products | NetApp Product Security | MISC | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.