Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3and MongoDB Server v3.6 versions prior to 3.6.18.



Advisories
Source ID Title
EUVD EUVD EUVD-2020-28852 Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3and MongoDB Server v3.6 versions prior to 3.6.18.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 18 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2024-11-18T17:30:33.314Z

Reserved: 2020-01-23T00:00:00

Link: CVE-2020-7921

cve-icon Vulnrichment

Updated: 2024-08-04T09:48:23.861Z

cve-icon NVD

Status : Modified

Published: 2020-05-06T15:15:11.880

Modified: 2024-11-21T05:38:00.877

Link: CVE-2020-7921

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-06-05T00:00:00Z

Links: CVE-2020-7921 - Bugzilla

cve-icon OpenCVE Enrichment

No data.