SB2019083012 - Security restrictions bypass in MongoDB



SB2019083012 - Security restrictions bypass in MongoDB

Published: August 30, 2019 Updated: September 24, 2019

Security Bulletin ID SB2019083012
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-2389)

The vulnerability allows a local user to kill arbitrary process on the system.

The vulnerability exists due to insufficient validation of data present in the PID file. A local user with write access to MongoDB PID file can insert arbitrary PIDs into it and kill arbitrary process on the system with root privileges, once MongoDB process is topped via SysV init.


Remediation

Install update from vendor's website.