mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\node_modules\. This issue affects mongosh prior to 2.3.0
2025-02-27T16:15:39.287
2025-04-09T14:07:26.960
Analyzed
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mongodb | mongosh | < 2.3.0 | Yes |
Application | redhat | codeready_linux_builder_eus | 9.4 | Yes |
Application | redhat | codeready_linux_builder_for_arm64_eus | 9.4_aarch64 | Yes |
Application | redhat | codeready_linux_builder_for_ibm_z_systems_eus | 9.4_s390x | Yes |
Application | redhat | codeready_linux_builder_for_power_little_endian_eus | 9.4_ppc64le | Yes |
Application | redhat | enterprise_linux_update_services_for_sap_solutions | 9.4 | Yes |
Operating System | redhat | enterprise_linux_eus | 9.4 | Yes |
Operating System | redhat | enterprise_linux_for_arm_64 | 9.4_aarch64 | Yes |
Operating System | redhat | enterprise_linux_for_arm_64_eus | 9.4_aarch64 | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems | 9.4_s390x | Yes |
Operating System | redhat | enterprise_linux_for_ibm_z_systems_eus | 9.4_s390x | Yes |
Operating System | redhat | enterprise_linux_for_power_little_endian_eus | 9.4_ppc64le | Yes |
Operating System | redhat | enterprise_linux_server_aus | 9.4 | Yes |