Bug 828318 (CVE-2013-4650) - VUL-0: CVE-2013-4650: mongodb: internal privilege escalation
Summary: VUL-0: CVE-2013-4650: mongodb: internal privilege escalation
Status: VERIFIED INVALID
Alias: CVE-2013-4650
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Jordi Massaguer
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2013-07-05 12:16 UTC by Marcus Meissner
Modified: 2013-07-15 11:22 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-07-05 12:16:18 UTC
via CVE db

CVE-2013-4650

MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of __system in an arbitrary database.

Reference: CONFIRM: https://jira.mongodb.org/browse/SERVER-9983
Reference: CONFIRM: http://www.mongodb.org/about/alerts/
Comment 1 Swamp Workflow Management 2013-07-05 22:00:25 UTC
bugbot adjusting priority
Comment 2 Flavio Castelli 2013-07-15 08:07:18 UTC
Mongodb is currently being used only by SUSE Studion onsite 1.3 AFAIK. Studio runs mongodb listening only over a local socket. Hence Studio is not affected by this vulnerability issue.

Assigning the bug to Jordi, how took over packing duties from me.
Comment 4 Sebastian Krahmer 2013-07-15 11:22:42 UTC
Ok. makes sense. closing