CVE-2020-7921Collapse of Data into Unsafe Value in INC Mongodb Server

Severity
5.3MEDIUMNVD
CNA4.6
EPSS
0.2%
top 60.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 24

Description

Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3and MongoDB Server v3.6 versions prior to 3.6.18.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

CVEListV5mongodb_inc/mongodb_server4.24.2.3+3
NVDmongodb/mongodb3.6.03.6.18+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4jqr-h7hr-v5mg: Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credenti2022-05-24
CVEList
Administrative action may disable enforcement of per-user IP whitelisting2020-05-06
OSV
CVE-2020-7921: Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credenti2020-05-06

📋Vendor Advisories

1
Red Hat
mongodb: Improper serialization permits bypass of IP based authentication restrictions2020-06-05

💬Community

2
Bugzilla
CVE-2020-7921 mongodb: Improper serialization permits bypass of IP based authentication restrictions [epel-all]2020-06-30
Bugzilla
CVE-2020-7921 mongodb: Improper serialization permits bypass of IP based authentication restrictions2020-06-18
CVE-2020-7921 — Collapse of Data into Unsafe Value | cvebase