Vulnerability Name: | CVE-2013-1892 (CCN-83054) | ||||||||||||
Assigned: | 2013-03-26 | ||||||||||||
Published: | 2013-03-26 | ||||||||||||
Updated: | 2023-02-13 | ||||||||||||
Summary: | MongoDB could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a type confusion error in the native_helper() function (engine_spidermonkey.cpp file). By persuading a victim to visit a specially-crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system or cause a denial of service. | ||||||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:F/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: secalert@redhat.com Type: Exploit secalert@redhat.com Source: MITRE Type: CNA CVE-2013-1892 Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: RHSA-2013-1170 Important: mongodb and pymongo security and enhancement update Source: secalert@redhat.com Type: Vendor Advisory secalert@redhat.com Source: CCN Type: SA52721 MongoDB "native_helper()" Type Confusion Vulnerability Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: MongoDB Web site MongoDB Source: secalert@redhat.com Type: Vendor Advisory secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: BID-58695 MongoDB CVE-2013-1892 Remote Code Injection Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 927536 CVE-2013-1892 MongoDB: Server Side JavaScript Includes allow Remote Code Execution Source: XF Type: UNKNOWN mongodb-cve20131892-code-exec(83054) Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: Packet Storm Security [04-02-2013] MongoDB nativeHelper.apply Remote Code Execution Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [04-08-2013] | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |