CyberRota Analysis
AI-GeneratedMongoDB Server's diagnostic reporting interface is vulnerable, allowing authenticated users with monitoring privileges to access unredacted credentials from concurrent administrative operations. This exposure of cleartext credentials could lead to impersonation of other users, including those with elevated privileges. Organizations using MongoDB should prioritize this issue to mitigate potential unauthorized access and protect sensitive data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. The same credentials are properly redacted in server log output, but the diagnostic interface omits equivalent redaction. Successful exploitation requires a valid authenticated session with monitoring-level permissions and results in exposure of cleartext credentials that could enable impersonation of other users, including privileged accounts.
Related CVEs
Other vulnerabilities affecting the same vendor(s)