CVE-2021-20334
Last modified
CVE-2021-20334 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Compass | >= 1.3.0, < 1.25.0 |
References
- https://jira.mongodb.org/browse/COMPASS-4510Vendor Advisory
- https://jira.mongodb.org/browse/COMPASS-4510Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20334?
How severe is CVE-2021-20334?
How do I fix CVE-2021-20334?
Are you affected by CVE-2021-20334?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
