CVE-2019-2389: Process termination via PID file manipulation
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects MongoDB Server v4.0 versions prior to 4.0.11; MongoDB Server v3.6 versions prior to 3.6.14; MongoDB Server v3.4 versions prior to 3.4.22.
Other sources
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.11; v3.6 versions prior to 3.6.14; v3.4 versions prior to 3.4.22.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-2389?
CVE-2019-2389 is a vulnerability in MongoDB Server's packaged SysV init scripts that allows users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init.
Which versions of MongoDB Server are affected by CVE-2019-2389?
MongoDB Server v3.4 to v4.0 versions (3.4.0 to 3.4.22, 3.6.0 to 3.6.14, 4.0.0 to 4.0.11) are affected by CVE-2019-2389.
How severe is CVE-2019-2389?
CVE-2019-2389 has a severity rating of 4.2 (medium).
How can I fix CVE-2019-2389?
To fix CVE-2019-2389, it is recommended to update MongoDB Server to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2019-2389?
More information about CVE-2019-2389 can be found at https://jira.mongodb.org/browse/SERVER-40563.