CyberRota Analysis
AI-GeneratedMongoDB Server is vulnerable due to a flaw in the server-side MozJS scripting engine, which allows authenticated users to leverage crafted aggregation pipeline commands to read arbitrary files from the host filesystem with the privileges of the mongod process. This could lead to unauthorized access to sensitive data, posing a significant risk to data confidentiality. Organizations using MongoDB, particularly those with user authentication enabled, should prioritize addressing this vulnerability to mitigate potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB server process.
Related CVEs
Other vulnerabilities affecting the same vendor(s)