Index: vuln.xml =================================================================== --- vuln.xml (revision 539558) +++ vuln.xml (working copy) @@ -58,6 +58,41 @@ * Do not forget port variants (linux-f10-libxml2, libxml2, etc.) --> + + MongoDB -- Ensure RoleGraph can serialize authentication restrictions to BSON + + + mongodb36 + 3.6.18 + + + mongodb40 + 4.0.15 + + + mongodb42 + 4.2.3 + + + + +

reports:

+
+

Improper serialization of MongoDB Server's internal authorization state permits a user with valid credentials to bypass IP source address protection mechanisms following administrative action.

+

Credit
+Discovered by Tony Yesudas.

+
+ +
+ + CVE-2020-7921 + + + 2020-01-10 + 2020-06-18 + +
+ Several issues in Lynis