Lucene search

K
redhatcveRedhat.comRH:CVE-2020-7921
HistoryJun 18, 2020 - 2:36 p.m.

CVE-2020-7921

2020-06-1814:36:57
redhat.com
access.redhat.com
13

0.001 Low

EPSS

Percentile

22.7%

A vulnerability was discovered in MongoDB, where an update operation on a user-define role clears the authenticationRestrictions field that was previously set. This unexpected behavior may remove previous IP based restrictions configured on a role, thus allowing a user to bypass them once the update operation is performed.

Mitigation

There is no known mitigation for this issue, the flaw can only be resolved by applying updates.