CyberRota Analysis
AI-GeneratedMongoDB Server is vulnerable due to an incorrect authorization issue in its aggregation framework, allowing authenticated users with minimal privileges to manipulate aggregation requests. This flaw can lead to unauthorized read access to sensitive collection data, potentially exposing confidential information. Organizations using MongoDB should prioritize addressing this vulnerability to mitigate risks associated with unauthorized data exposure.
Original NVD Description
MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that causes the server's authorization subsystem to evaluate a different operation than what is actually executed, resulting in unauthorized read access to collection data within the target database.
Related CVEs
Other vulnerabilities affecting the same vendor(s)