MongoDB Remote Privilege Escalation Vulnerability
BID:61007
Info
MongoDB Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 61007 |
| Class: | Access Validation Error |
| CVE: |
CVE-2013-4650 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2013 12:00AM |
| Updated: | Jul 05 2013 12:00AM |
| Credit: | Spencer Brody |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
MongoDB Remote Privilege Escalation Vulnerability
MongoDB is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges within the application and obtain unauthorized access to the sensitive information.
MongoDB 2.4.0 through 2.4.4 and 2.5.0 are vulnerable; other versions may also be affected.
MongoDB is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges within the application and obtain unauthorized access to the sensitive information.
MongoDB 2.4.0 through 2.4.4 and 2.5.0 are vulnerable; other versions may also be affected.
Exploit / POC
MongoDB Remote Privilege Escalation Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
MongoDB Remote Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
MongoDB Remote Privilege Escalation Vulnerability
References:
References: