CVE-2023-4009
In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.76%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.76% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-648, CWE-269
- Affected
- mongodb/ops manager server
- Source
- cna@mongodb.com
References
- https://security.netapp.com/advisory/ntap-20230831-0013/
- https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#onprem-server-6-0Vendor Advisory
- https://www.mongodb.com/docs/ops-manager/v5.0/release-notes/application/#onprem-server-5-0-22Vendor Advisory
- https://security.netapp.com/advisory/ntap-20230831-0013/
- https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#onprem-server-6-0Vendor Advisory
- https://www.mongodb.com/docs/ops-manager/v5.0/release-notes/application/#onprem-server-5-0-22Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.