CVE-2025-3082: User may override a view's collation and gain unauthorized access to underlying data
A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3082?
CVE-2025-3082 has a critical severity rating due to its potential to allow unauthorized data access.
How do I fix CVE-2025-3082?
To mitigate CVE-2025-3082, upgrade MongoDB Server to version 5.0.31 or later, 6.0.20 or later, or 7.0.14 or later.
What versions of MongoDB Server are affected by CVE-2025-3082?
CVE-2025-3082 affects MongoDB Server versions prior to 5.0.31, 6.0.20, and 7.0.14.
What type of vulnerability is CVE-2025-3082?
CVE-2025-3082 is a privilege escalation vulnerability that allows users to alter data visibility.
Can this vulnerability lead to data breaches in MongoDB Server?
Yes, CVE-2025-3082 can lead to data breaches by enabling unauthorized access to sensitive data.