MongoDB Server
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*
- >= 5.0, < 5.0.31
- >= 6.0, < 6.0.24
- >= 7.0, < 7.0.21
- >= 8.0, < 8.0.5
A race condition vulnerability has been identified in MongoDB Server that allows an authenticated user request to be executed with outdated privileges. This issue arises after an authorized administrator makes a change, and it affects MongoDB Server versions 5.0 prior to 5.0.31, 6.0 prior to 6.0.24, 7.0 prior to 7.0.21, and 8.0 prior to 8.0.5.
Exploitation of this vulnerability can lead to incorrect authorization, allowing users to retain stale privileges after an administrator has made changes.
The vulnerability can be reproduced by an authenticated user who requests privileges shortly after an administrator has made changes to privilege assignments. This can create a window where the user's request is processed with the old privileges, before the changes take effect.
Users can upgrade to MongoDB Server versions 5.0.31, 6.0.24, 7.0.21, or 8.0.5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.