MongoDB Ops Manager
cpe:2.3:a:mongodb:ops_manager:*:*:*:*:*:*:*
- ~7.0
- ~8.0.0, <= 8.0.22
A vulnerability exists in MongoDB Ops Manager that allows an administrative user to execute arbitrary commands by configuring webhooks with specific FreeMarker template syntax and then triggering those webhooks. This issue affects all MongoDB Ops Manager 7.0 versions and MongoDB Ops Manager versions 8.0.22 and prior.
Exploitation of this vulnerability allows for arbitrary command execution on the server where MongoDB Ops Manager is running.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.