CVE-2020-7927: Potential privilege escalation in Ops Manager API
Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions 4.2.0-4.2.17, v4.3 versions 4.3.0-4.3.9 and v4.4 versions 4.4.0-4.4.2.
Other sources
Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions prior to and including 4.2.17, MongoDB Ops Manager v4.3 versions prior to and including 4.3.9 and MongoDB Ops Manager v4.4 versions prior to and including 4.4.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7927?
CVE-2020-7927 is a vulnerability in MongoDB Ops Manager that allows an authenticated user with Organization Owner privilege to obtain an API key with Global Role privilege.
Which versions of MongoDB Ops Manager are affected by CVE-2020-7927?
CVE-2020-7927 affects MongoDB Ops Manager v4.2 versions 4.2.0-4.2.17, v4.3 versions 4.3.0-4.3.9, and v4.4 versions 4.4.0-4.4.2.
What is the severity of CVE-2020-7927?
The severity of CVE-2020-7927 is high with a CVSS score of 6.5.
How can I fix CVE-2020-7927?
To fix CVE-2020-7927, you should update MongoDB Ops Manager to version 4.4.3 or later.
Where can I find more information about CVE-2020-7927?
You can find more information about CVE-2020-7927 in the MongoDB Ops Manager release notes: https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-4-3