Back

CRITICAL

Authentication bypass when using LDAP authentication in MongoDB Enterprise Server

Published Jul 19, 2019

Description

Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

Affected products

Remediation

Red Hat statement

All versions of the following products which include mongodb include only MongoDB's Community edition, and are therefore not affected by this vulnerability: * Red Hat OpenStack Platform * Red Hat Software Collections * Red Hat Update Infrastructure

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 19, 2019
Updated Aug 6, 2024
Reserved Oct 21, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 29, 2015