PT-2019-4123 · Openssl+2 · Openssl+3

Rich Mirch

·

Published

2019-07-15

·

Updated

2026-02-23

·

CVE-2019-2390

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MongoDB Server versions prior to 4.0.11 MongoDB Server versions prior to 3.6.14 MongoDB Server versions prior to 3.4.22
Description The issue is related to insufficient access control in the MongoDB database management system. An unprivileged user or program on Microsoft Windows that can create OpenSSL configuration files in a fixed location may cause utility programs shipped with the MongoDB server to run attacker-defined code as the user running the utility.
Recommendations For MongoDB Server versions prior to 4.0.11, update to version 4.0.11 or later. For MongoDB Server versions prior to 3.6.14, update to version 3.6.14 or later. For MongoDB Server versions prior to 3.4.22, update to version 3.4.22 or later.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04702
CVE-2019-2390

Affected Products

Windows
Mongodb Server
Mongodb
Openssl