Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mitch Wasson

#41266of 56,330
7.1Total CVSS
Vulnerabilities · 1
PT-2019-16408
7.1
2019-08-06
Mongodb · Mongodb Server · CVE-2019-2386
**Name of the Vulnerable Software and Affected Versions** MongoDB Server versions prior to 4.0.9 MongoDB Server versions prior to 3.6.13 MongoDB Server versions prior to 3.4.22 **Description** The improper invalidation of authorization sessions in MongoDB Server allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. **Recommendations** For MongoDB Server versions prior to 4.0.9, restart any nodes which may have had active user authorization sessions after deleting one or more users, and refrain from creating user accounts with the same name as previously deleted accounts. For MongoDB Server versions prior to 3.6.13, restart any nodes which may have had active user authorization sessions after deleting one or more users, and refrain from creating user accounts with the same name as previously deleted accounts. For MongoDB Server versions prior to 3.4.22, restart any nodes which may have had active user authorization sessions after deleting one or more users, and refrain from creating user accounts with the same name as previously deleted accounts.