7.2
CVSSv3

CVE-2023-4009

Published: 08/08/2023 Updated: 31/08/2023
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

In MongoDB Ops Manager v5.0 before 5.0.22 and v6.0 before 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.

Vulnerable Product Search on Vulmon Subscribe to Product

mongodb ops manager server