An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22
References
Link | Resource |
---|---|
https://jira.mongodb.org/browse/SERVER-106752 |
Configurations
No configuration.
History
18 Jul 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.0 versions prior to 6.0.22 |
08 Jul 2025, 16:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-07 15:15
Updated : 2025-07-18 06:15
NVD link : CVE-2025-6713
Mitre link : CVE-2025-6713
CVE.ORG link : CVE-2025-6713
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization