Deserializing compromised object with MongoDB .NET/C# Driver may cause remote code execution
Published Feb 21, 2023
7.2
HIGHCVSS 3.1
EPSS 1.38%
Description
Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which may cause further disruption to services. This is specific to applications written in C#. This affects all MongoDB .NET/C# Driver versions prior to and including v2.18.0
Following configuration must be true for the vulnerability to be applicable: * Application must written in C# taking arbitrary data from users and serializing data using _t without any validation AND * Application must be running on a Windows host using the full .NET Framework, not .NET Core AND * Application must have domain model class with a property/field explicitly of type System.Object or a collection of type System.Object (against MongoDB best practice) AND * Malicious attacker must have unrestricted insert access to target database to add a _t discriminator."Following configuration must be true for the vulnerability to be applicable
Affected products
-
- Version 0StatusaffectedConstraints<=v2.18.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| MongoDB Inc | MongoDB .NET/C# Driver | unaffected |
|
- < 2.19.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://github.com/advisories/GHSA-7j9m-j397-g4wx Advisory
- https://github.com/mongodb/mongo-csharp-driver/releases/tag/v2.19.0 Release Notes
- https://jira.mongodb.org/CSHARP-4475
- https://jira.mongodb.org/browse/CSHARP-4475 PatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-48282
- https://security.netapp.com/advisory/ntap-20230324-0003/
Change history (0)
No recorded changes yet.