MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
References
Link | Resource |
---|---|
https://jira.mongodb.org/browse/COMPASS-9058 | Vendor Advisory Issue Tracking |
https://access.redhat.com/errata/RHSA-2025:1755.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
|
History
09 Apr 2025, 14:07
Type | Values Removed | Values Added |
---|---|---|
References | () https://jira.mongodb.org/browse/COMPASS-9058 - Vendor Advisory, Issue Tracking | |
References | () https://access.redhat.com/errata/RHSA-2025:1755.html - Third Party Advisory | |
Summary |
|
|
CPE | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:* cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:* |
|
First Time |
Mongodb compass
Redhat enterprise Linux For Ibm Z Systems Redhat enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Redhat enterprise Linux For Arm 64 Microsoft windows Microsoft Redhat Mongodb Redhat enterprise Linux Update Services For Sap Solutions |
27 Feb 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-27 16:15
Updated : 2025-04-09 14:07
NVD link : CVE-2025-1755
Mitre link : CVE-2025-1755
CVE.ORG link : CVE-2025-1755
JSON object : View
Products Affected
redhat
- enterprise_linux_for_ibm_z_systems
- enterprise_linux_update_services_for_sap_solutions
- enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
- enterprise_linux_for_arm_64
microsoft
- windows
mongodb
- compass
CWE
CWE-426
Untrusted Search Path