Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions prior to and including 4.2.17, MongoDB Ops Manager v4.3 versions prior to and including 4.3.9 and MongoDB Ops Manager v4.4 versions prior to and including 4.4.2.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:38
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 8.1 |
References | () https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#onprem-server-4.4.3 - |
17 Sep 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions prior to and including 4.2.17, MongoDB Ops Manager v4.3 versions prior to and including 4.3.9 and MongoDB Ops Manager v4.4 versions prior to and including 4.4.2. |
23 Jan 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions prior to and including 4.2.17, MongoDB Ops Manager v4.3 versions prior to and including 4.3.9 and MongoDB Ops Manager v4.4 versions prior to and including 4.4.2. | |
References |
|
|
Information
Published : 2020-11-23 19:15
Updated : 2024-11-21 05:38
NVD link : CVE-2020-7927
Mitre link : CVE-2020-7927
CVE.ORG link : CVE-2020-7927
JSON object : View
Products Affected
mongodb
- ops_manager
CWE