First published: Mon Jan 25 2016(Updated: )
Jan Hutař of Red Hat reports: MongoDB on Satellite 6 is configured without a password by default, this allows local users to connect to MongoDB and cause information to be deleted.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
MongoDB | ||
Red Hat Satellite | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8180 is considered a high severity vulnerability due to the potential for local users to manipulate and delete data without authentication.
The fix for CVE-2014-8180 involves configuring MongoDB to require a password for local users.
CVE-2014-8180 affects installations of MongoDB configured without a password on Red Hat Satellite 6.
The potential risks of CVE-2014-8180 include unauthorized access, data deletion, and loss of critical information by local users.
CVE-2014-8180 impacts MongoDB server versions integrated with Red Hat Satellite 6, specifically version 6.0.