Impact
MongoDB Server's diagnostic reporting interface fails to redact credentials that are otherwise masked in log output. When accessed by an authenticated user with monitoring privileges, cleartext credentials from concurrent administrative operations can be viewed. Exposure of these credentials could allow an attacker to impersonate other users, including those with elevated or privileged access. The flaw is represented by CWE-522 and results in a confidentiality compromise for user credentials.
Affected Systems
The vulnerability affects MongoDB Server. No specific version numbers are listed in the CNA data; any instance of MongoDB Server that implements the diagnostic reporting interface is potentially impacted. Users running MongoDB Server should verify if they have enabled monitoring privileges and the diagnostic reporting feature.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium to high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires a valid authenticated session with monitoring-level permissions; Based on the description, it is inferred that no publicly disclosed exploit path is currently known. Because monitoring privileges are typically limited, the potential impact depends heavily on the privileges assigned to those users. Organizations should assess whether monitoring roles are assigned to trusted accounts and consider patching.
OpenCVE Enrichment