CVE-2019-2389

Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects MongoDB Server v4.0 versions prior to 4.0.11; MongoDB Server v3.6 versions prior to 3.6.14; MongoDB Server v3.4 versions prior to 3.4.22.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-40563 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-08-30 15:15

Updated : 2024-01-23 15:15


NVD link : CVE-2019-2389

Mitre link : CVE-2019-2389

CVE.ORG link : CVE-2019-2389


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-20

Improper Input Validation

CWE-732

Incorrect Permission Assignment for Critical Resource