Skip to content

CVE-2023-4009 | MongoDB Ops Manager

In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation. .This CVE has a CVSS3.1 score of 7.2 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-4009
CVE StatePUBLISHED
BaseScore7.2
BaseSeverityHIGH
VectorStringCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
VersionNA

References for CVE-2023-4009 :
https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#onprem-server-6-0
https://www.mongodb.com/docs/ops-manager/v5.0/release-notes/application/#onprem-server-5-0-22
https://security.netapp.com/advisory/ntap-20230831-0013/

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)HIGH
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)HIGH
Availability(A)HIGH
Integrity(I)HIGH