PT-2025-36330 · Mongodb+1 · Mongodb Server+2

CVE-2025-10060

·

Publicado

2024-10-04

·

Atualizado

2025-10-20

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MongoDB Server versions prior to 6.0.25 MongoDB Server versions prior to 7.0.22 MongoDB Server versions prior to 8.0.12
Description MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure and server crash during commit. This issue may be triggered by improper WriteUnitOfWork state management.
Recommendations Upgrade MongoDB Server to version 6.0.25 or later. Upgrade MongoDB Server to version 7.0.22 or later. Upgrade MongoDB Server to version 8.0.12 or later.

Exploit

Correção

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-12673
BIT-MONGODB-2025-10060
CVE-2025-10060

Produtos afetados

Mongodb Server
Mongodb
Red Os