MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
References
Link | Resource |
---|---|
https://jira.mongodb.org/browse/COMPASS-9058 | Vendor Advisory Issue Tracking |
https://access.redhat.com/errata/RHSA-2025:1755.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
|
History
09 Apr 2025, 14:07
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://jira.mongodb.org/browse/COMPASS-9058 - Vendor Advisory, Issue Tracking | |
References | () https://access.redhat.com/errata/RHSA-2025:1755.html - Third Party Advisory | |
First Time |
Redhat enterprise Linux Update Services For Sap Solutions
Redhat Redhat enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Microsoft Redhat enterprise Linux For Arm 64 Microsoft windows Mongodb compass Mongodb Redhat enterprise Linux For Ibm Z Systems |
|
CPE | cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:* cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:* |
27 Feb 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-27 16:15
Updated : 2025-04-09 14:07
NVD link : CVE-2025-1755
Mitre link : CVE-2025-1755
CVE.ORG link : CVE-2025-1755
JSON object : View
Products Affected
redhat
- enterprise_linux_for_ibm_z_systems
- enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
- enterprise_linux_for_arm_64
- enterprise_linux_update_services_for_sap_solutions
mongodb
- compass
microsoft
- windows
CWE
CWE-426
Untrusted Search Path