U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalog
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户的要求是直接写文章描述,不需要特定的开头。 首先,我得仔细阅读文章内容。文章主要讲的是美国CISA机构将MongoDB Server的一个漏洞CVE-2025-14847添加到了已知被利用的漏洞目录中。这个漏洞的CVSS评分为8.7,属于高危漏洞。 接下来,文章提到这个漏洞被称为MongoBleed,已经被积极利用,全球有超过87,000个潜在受影响的实例。攻击者无需认证即可泄露服务器内存中的敏感数据,包括用户详情、密码和API密钥。 然后,文章还提到该漏洞影响多个MongoDB版本,并建议用户升级到修复版本或禁用zlib压缩。CISA要求联邦机构在2026年1月19日前修复此漏洞。 现在我需要把这些关键点浓缩到100字以内。重点包括:CISA添加了MongoDB Server的高危漏洞CVE-2025-14847到KEV目录中;该漏洞允许未认证攻击者泄露敏感数据;影响多个版本;CISA要求修复期限。 最后,确保语言简洁明了,不使用复杂的术语,并且直接描述内容。 </think> 美国网络安全和基础设施安全局(CISA)将MongoDB Server的一个高危漏洞CVE-2025-14847(CVSS评分8.7)添加到其已知被利用的漏洞目录中。该漏洞允许未认证攻击者泄露敏感服务器内存数据,影响多个MongoDB版本。CISA要求联邦机构在2026年1月19日前修复此漏洞。 2025-12-30 08:33:56 Author: securityaffairs.com(查看原文) 阅读量:11 收藏

U.S. CISA adds a flaw in MongoDB Server to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini December 30, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a MongoDB Server flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a MongoDB Server vulnerability, tracked as CVE-2025-14847 (CVSS Score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog.

The recently disclosed MongoDB vulnerability CVE-2025-14847 (aka MongoBleed) is being actively exploited, with more than 87,000 potentially vulnerable instances identified worldwide.

Cybersecurity researcher Joe Desimone published a proof-of-concept exploit for this vulnerability that allows unauthenticated attackers to leak sensitive server memory.

According to Censys, most of the potentially vulnerable instances are in the U.S., China, Germany, and India.

“A working exploit has been publicly available since December 26, 2025, with initial reporting of exploitation in the wild reported shortly after.” reads the report published by cybersecurity firm Wiz.

At this time, attack details remain unclear.

MongoDB
Source Censys

MongoDB is a popular open-source NoSQL database used to store and manage data in a flexible, document-based format.

Instead of tables and rows like traditional SQL databases, MongoDB stores data as JSON-like documents (called BSON). This makes it well-suited for modern applications that need scalability, high performance, and flexible data models.

The vulnerability CVE-2025-14847 can allow an unauthenticated, remote attacker to execute arbitrary code on vulnerable servers.

“An client-side exploit of the Server’s zlib implementation can return uninitialized heap memory without authenticating to the server. We strongly recommend upgrading to a fixed version as soon as possible.” reads the advisory.

The issue stems zlib message decompression, which is enabled by default, and allows unauthenticated attackers to leak data from MongoDB servers at the network level. The vulnerability impacts publicly exposed instances and reachable private servers. Exploitation can lead to gradual extraction of sensitive data such as user details, passwords, and API keys.

This flaw impacts the following MongoDB versions:

  • MongoDB 8.2.0 through 8.2.3
  • MongoDB 8.0.0 through 8.0.16
  • MongoDB 7.0.0 through 7.0.26
  • MongoDB 6.0.0 through 6.0.26
  • MongoDB 5.0.0 through 5.0.31
  • MongoDB 4.4.0 through 4.4.29
  • All MongoDB Server v4.2 versions
  • All MongoDB Server v4.0 versions
  • All MongoDB Server v3.6 versions

Versions 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, and 4.4.30 addressed the issue.

Users should upgrade immediately or, if unable, disable zlib compression on MongoDB by configuring compression options to omit zlib.

“We strongly suggest you upgrade immediately.” continues the advisory. “If you cannot upgrade immediately, disable zlib compression on the MongoDB Server by starting mongod or mongos with a networkMessageCompressors or a net.compression.compressors option that explicitly omits zlib. Example safe values include snappy,zstd or disabled”

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by January 19, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)




文章来源: https://securityaffairs.com/186297/hacking/u-s-cisa-adds-a-flaw-in-mongodb-server-to-its-known-exploited-vulnerabilities-catalog.html
如有侵权请联系:admin#unsafe.sh