7.1 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
22 packages
- mongodb-cli
- mongodb-compass
- mongodb-atlas-cli
- phpExtensions.mongodb
- haskellPackages.mongoDB
- php82Extensions.mongodb
- php83Extensions.mongodb
- php84Extensions.mongodb
- php85Extensions.mongodb
- akkuPackages.r6rs-mongodb
- prometheus-mongodb-exporter
- haskellPackages.pipes-mongodb
- graylogPlugins.mongodb-profiler
- terraform-providers.mongodbatlas
- python313Packages.langchain-mongodb
- python314Packages.langchain-mongodb
- terraform-providers.mongodb_mongodbatlas
- vscode-extensions.mongodb.mongodb-vscode
- python313Packages.langgraph-store-mongodb
- python314Packages.langgraph-store-mongodb
- python313Packages.langgraph-checkpoint-mongodb
- python314Packages.langgraph-checkpoint-mongodb
- @LeSuisse accepted
- @LeSuisse published on GitHub
Stack memory disclosure in filemd5 command
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
Affected products
- <8.3.3
- <8.2.10
Matching in nixpkgs
pkgs.mongodb
Scalable, high-performance, open source NoSQL database
pkgs.mongodb-ce
MongoDB is a general purpose, document-based, distributed database
Ignored packages (22)
pkgs.mongodb-cli
Manage your MongoDB via ops manager and cloud manager
pkgs.mongodb-compass
GUI for MongoDB
pkgs.mongodb-atlas-cli
CLI utility to manage MongoDB Atlas from the terminal
pkgs.phpExtensions.mongodb
Official MongoDB PHP driver
pkgs.haskellPackages.mongoDB
Driver (client) for MongoDB, a free, scalable, fast, document DBMS
pkgs.php82Extensions.mongodb
Official MongoDB PHP driver
pkgs.php83Extensions.mongodb
Official MongoDB PHP driver
pkgs.php84Extensions.mongodb
Official MongoDB PHP driver
pkgs.php85Extensions.mongodb
Official MongoDB PHP driver
pkgs.akkuPackages.r6rs-mongodb
MongoDB client and BSON
-
nixos-unstable r6rs-mongodb-0.0.190423
- nixpkgs-unstable r6rs-mongodb-0.0.190423
- nixos-unstable-small r6rs-mongodb-0.0.190423
-
nixos-26.05 r6rs-mongodb-0.0.190423
- nixos-26.05-small r6rs-mongodb-0.0.190423
- nixpkgs-26.05-darwin r6rs-mongodb-0.0.190423
pkgs.prometheus-mongodb-exporter
Prometheus exporter for MongoDB including sharding, replication and storage engines
pkgs.haskellPackages.pipes-mongodb
Stream results from MongoDB
pkgs.graylogPlugins.mongodb-profiler
Graylog input plugin that reads MongoDB profiler data
pkgs.terraform-providers.mongodbatlas
None
pkgs.python313Packages.langchain-mongodb
Integration package connecting MongoDB and LangChain
pkgs.python314Packages.langchain-mongodb
Integration package connecting MongoDB and LangChain
pkgs.terraform-providers.mongodb_mongodbatlas
None
pkgs.vscode-extensions.mongodb.mongodb-vscode
Extension for VS Code that makes it easy to work with your data in MongoDB
pkgs.python313Packages.langgraph-store-mongodb
Integrations between MongoDB, Atlas, LangChain, and LangGraph
pkgs.python314Packages.langgraph-store-mongodb
Integrations between MongoDB, Atlas, LangChain, and LangGraph
pkgs.python313Packages.langgraph-checkpoint-mongodb
Integrations between MongoDB, Atlas, LangChain, and LangGraph