All errata/sisyphus/ALT-PU-2020-4247-1
ALT-PU-2020-4247-1

Package update mongo in branch sisyphus

Version4.2.3-alt1
Published2020-02-05
Max severityMEDIUM
Severity:

Closed issues (2)

BDU:2020-03363
MEDIUM4.6

Уязвимость документоориентированной системы управления базами данных MongoDB, связанная с ошибками авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

Published: 2020-07-17
CVSS 3.xMEDIUM 4.6
CVSS:3.x/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CVSS 2.0MEDIUM 4.9
CVSS:2.0/AV:N/AC:M/Au:S/C:P/I:P/A:N
References
CVE-2020-7921
MEDIUM5.3

Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3and MongoDB Server v3.6 versions prior to 3.6.18.

Published: 2020-05-06Modified: 2026-02-23
CVSS 2.0LOW 3.5
CVSS:2.0/AV:N/AC:M/Au:S/C:N/I:P/A:N
CVSS 3.xMEDIUM 5.3
CVSS:3.x/CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N