CNNVD-202507-689 Information

CNNVD ID

CNNVD-202507-689

CVE-2025-6713

  • CNNVD Published: 2025-07-07

Description (Chinese)

MongoDB Server是美国MongoDB公司的一套开源的NoSQL数据库。该数据库提供面向集合的存储、动态查询、数据复制及自动故障转移等功能。 MongoDB Server 8.0.7之前版本、7.0.20之前版本和6.0.22之前版本存在安全漏洞,该漏洞源于对$mergeCursors阶段处理不当,可能导致未授权数据访问。

Description (English)

MongoDB Server is an open-source NoSQL database for MongoDB in the United States. The database provides a collection-oriented memory, dynamic queries, data replication and automatic downtime transfer. There is a security loophole in the pre-MongoDB Server 8.0.7, pre-Sept. 7.0.20 and pre-Sept. 6.0.22, which stems from the mishandling of the MergeCursors phase, which may lead to unauthorized data access.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

MongoDB

Published

2025-07-07

Last Modified

2026-02-24

References

https://jira.mongodb.org/browse/SERVER-106752 https://vigilance.fr/vulnerability/MongoDB-Server-privilege-escalation-via-MergeCursors-Stage-47620

Patch

https://www.mongodb.com/docs/manual/release-notes/8.0/#std-label-release-notes-8.0

Share on: