VDB
CVE-2013-1892
CVE-2013-1892
PUBLISHED
CVSS 6 MEDIUM
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.
EPSS 52.17% · 98.0th percentile
Risk Scores
CVSS 2.0
6
EPSS Score
52.17%
98.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mongodb | mongodb | 2.0.4, 2.0.7, 2.0.5 |
| n/a | n/a | n/a |
| redhat | enterprise_mrg | 2.3 |
Timeline
- Apr 2, 2013 PoC Published
- Apr 8, 2013 PoC Published
- Oct 1, 2013 CVE Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 14, 2023 EPSS Score
- Sep 30, 2023 EPSS Score
- Nov 18, 2023 EPSS Score
- Jan 5, 2024 EPSS Score
- Dec 17, 2024 EPSS Score
References
- RHSA-2013:1170 vendor-advisory
- 24947 exploit
- [oss-security] 20130325 Re: CVE Request: Mongo DB mailing-list
- FEDORA-2013-4539 vendor-advisory
- http://blog.scrt.ch/2013/03/24/mongodb-0-day-ssji-to-rce/ url
- 24935 exploit
- https://jira.mongodb.org/browse/SERVER-9124 url
- http://www.mongodb.org/about/alerts/ url
- FEDORA-2013-4531 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-1892 advisory
- https://access.redhat.com/errata/RHSA-2013:1170 url
- https://access.redhat.com/security/cve/CVE-2013-1892 url
- https://bugzilla.redhat.com/show_bug.cgi?id=927536 url
- http://blog.scrt.ch/2013/03/24/mongodb-0-day-ssji-to-rce url
- http://www.mongodb.org/about/alerts url