git: a66fafb28afb - main - security/vuxml: Add mongodb vulnerability
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Mon, 18 Nov 2024 16:16:41 UTC
The branch main has been updated by fernape: URL: https://cgit.FreeBSD.org/ports/commit/?id=a66fafb28afbb4bee5df45606f236342e373ac21 commit a66fafb28afbb4bee5df45606f236342e373ac21 Author: Fernando Apesteguía <fernape@FreeBSD.org> AuthorDate: 2024-11-17 18:26:50 +0000 Commit: Fernando Apesteguía <fernape@FreeBSD.org> CommitDate: 2024-11-18 16:16:23 +0000 security/vuxml: Add mongodb vulnerability Buffer over-read. --- security/vuxml/vuln/2024.xml | 41 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 41 insertions(+) diff --git a/security/vuxml/vuln/2024.xml b/security/vuxml/vuln/2024.xml index d0b085c04287..edbdf9479bbf 100644 --- a/security/vuxml/vuln/2024.xml +++ b/security/vuxml/vuln/2024.xml @@ -1,3 +1,44 @@ + <vuln vid="28ffa931-a510-11ef-8109-b42e991fc52e"> + <topic>mongodb -- Buffer over-reads in MongoDB Server</topic> + <affects> + <package> + <name>mongodb50</name> + <range><lt>5.0.30</lt></range> + </package> + <package> + <name>mongodb60</name> + <range><lt>6.0.19</lt></range> + </package> + <package> + <name>mongodb70</name> + <range><lt>7.0.15</lt></range> + </package> + <package> + <name>mongodb80</name> + <range><lt>8.0.2</lt></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>cna@mongodb.com reports:</p> + <blockquote cite="https://jira.mongodb.org/browse/SERVER-96419"> + <p>An authorized user may trigger crashes or receive the contents of + buffer over-reads of Server memory by issuing specially crafted + requests that construct malformed BSON in the MongoDB Server. + </p> + </blockquote> + </body> + </description> + <references> + <cvename>CVE-2024-10921</cvename> + <url>https://nvd.nist.gov/vuln/detail/CVE-2024-10921</url> + </references> + <dates> + <discovery>2024-11-14</discovery> + <entry>2024-11-17</entry> + </dates> + </vuln> + <vuln vid="aba28514-a414-11ef-98e7-84a93843eb75"> <topic>Vaultwarden -- Multiple vulnerabilities</topic> <affects>