Bugzilla – Bug 828318
VUL-0: CVE-2013-4650: mongodb: internal privilege escalation
Last modified: 2013-07-15 11:22:42 UTC
via CVE db CVE-2013-4650 MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of __system in an arbitrary database. Reference: CONFIRM: https://jira.mongodb.org/browse/SERVER-9983 Reference: CONFIRM: http://www.mongodb.org/about/alerts/
bugbot adjusting priority
Mongodb is currently being used only by SUSE Studion onsite 1.3 AFAIK. Studio runs mongodb listening only over a local socket. Hence Studio is not affected by this vulnerability issue. Assigning the bug to Jordi, how took over packing duties from me.
Ok. makes sense. closing