CVE-2013-1892 is a critical vulnerability affecting MongoDB versions before 2.0.9 and 2.2.x before 2.2.4, as well as associated Red Hat products. This flaw allows remote authenticated users to trigger a denial of service or execute arbitrary code by sending a specially crafted request to the nativeHelper function. With a CVSS score of 6.0 and a FAUCET Risk Score of 98/100, this vulnerability presents a significant risk due to its network-based attack vector, medium attack complexity, and potential for partial confidentiality, integrity, and availability impacts. Exploit code is publicly available through Metasploit modules and ExploitDB, indicating a high likelihood of exploitation, although it is not currently listed on CISA's KEV catalog. The vulnerability has garnered notable community discussion and media coverage, further highlighting its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.8CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | ||
1.2.0CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:1.2.0:*:*:*:*:*:*:* | ||
1.4.0CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:1.4.0:*:*:*:*:*:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:1.6.0:*:*:*:*:*:*:* | ||
1.8.0CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:1.8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.