MongoDB Inc Vulnerabilities and Affected Products
Vulnerabilities associated with MongoDB .NET/C# Driver.
Products
Clear product- MongoDB Server41 vulnerabilities
- MongoDB C Driver4 vulnerabilities
- mongosh4 vulnerabilities
- libbson3 vulnerabilities
- MongoDB Compass3 vulnerabilities
- MongoDB PHP Driver2 vulnerabilities
- Mongo_crypt_v1.so1 vulnerability
- mongocryptd1 vulnerability
- MongoDB .NET/C# Driver1 vulnerability
- MongoDB Atlas Kubernetes Operator1 vulnerability
- MongoDB C++ Driver1 vulnerability
- MongoDB Connector for BI1 vulnerability
- MongoDB Go Driver1 vulnerability
- MongoDB Node.js Driver1 vulnerability
- MongoDB Ruby Driver1 vulnerability
- MongoDB Rust Driver1 vulnerability
- MongoDB Swift Driver1 vulnerability
- PyMongo1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-48282MEDIUM | Deserializing compromised object with MongoDB .NET/C# Driver may cause remote code executionUnder very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which may cause further disruption to services. This is specific to applications written in C#. This affects all MongoDB .NET/C# Driver versions prior to and including v2.18.0 Following configuration must be true for the vulnerability to be applicable: * Application must written in C# taking arbitrary data from users and serializing data using _t witho… CWE-502Feb 21, 2023 | CVSS6.6v3.1 | EPSS1.38% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |