Access Control Flaw in MongoDB Server by MongoDB, Inc.
CVE-2025-3082
3.1LOW
Key Information:
- Vendor
MongoDB
- Status
- Vendor
- CVE Published:
- 1 April 2025
What is CVE-2025-3082?
An access control issue has been identified in MongoDB Server, where an authorized user can manipulate the collation settings, potentially gaining access to unauthorized data views. This vulnerability impacts multiple versions of the MongoDB Server, making it critical for users to ensure they are running the latest versions to mitigate risks.
Affected Version(s)
MongoDB Server 5.0 < 5.0.31
MongoDB Server 6.0 < 6.0.20
MongoDB Server 7.0 < 7.0.14