Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which may cause further disruption to services. This is specific to applications written in C#. This affects all MongoDB .NET/C# Driver versions prior to and including v2.18.0
References
Link | Resource |
---|---|
https://github.com/mongodb/mongo-csharp-driver/releases/tag/v2.19.0 | Release Notes |
https://jira.mongodb.org/browse/CSHARP-4475 | Patch Vendor Advisory |
Configurations
Information
Published : 2023-02-21 11:15
Updated : 2023-03-02 14:50
NVD link : CVE-2022-48282
Mitre link : CVE-2022-48282
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
mongodb
- c\#_driver