MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
History

Wed, 09 Apr 2025 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Redhat
Redhat enterprise Linux For Arm 64
Redhat enterprise Linux For Ibm Z Systems
Redhat enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
Redhat enterprise Linux Update Services For Sap Solutions
CPEs cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:9.0_aarch64:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:9.0_s390x:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions:9.0_ppc64le:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_update_services_for_sap_solutions:9.0:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows
Redhat
Redhat enterprise Linux For Arm 64
Redhat enterprise Linux For Ibm Z Systems
Redhat enterprise Linux Server For Power Little Endian Update Services For Sap Solutions
Redhat enterprise Linux Update Services For Sap Solutions

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
References

Thu, 27 Feb 2025 15:30:00 +0000

Type Values Removed Values Added
Description MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1
Title MongoDB Compass may be susceptible to local privilege escalation in Windows
First Time appeared Mongodb
Mongodb compass
Weaknesses CWE-426
CPEs cpe:2.3:a:mongodb:compass:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.10:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.11:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.12:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.13:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.14:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.15:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.16:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.17:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.18:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.19:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.20:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.21:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.22:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.23:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.24.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.25.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.26.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.26.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.28.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.28.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.29.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.29.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.29.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.30.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.31.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.31.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.31.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.31.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.32.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.32.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.32.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.32.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.33.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.33.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.34.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.34.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.35.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.36.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.36.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.37.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.38.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.38.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.38.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.39.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.40.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.41.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.42.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.7:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.8:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:compass:1.9:*:*:*:*:*:*:*
Vendors & Products Mongodb
Mongodb compass
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2025-02-27T16:07:45.320Z

Reserved: 2025-02-27T13:02:01.480Z

Link: CVE-2025-1755

cve-icon Vulnrichment

Updated: 2025-02-27T16:07:09.984Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-27T16:15:39.137

Modified: 2025-04-09T14:07:43.140

Link: CVE-2025-1755

cve-icon Redhat

No data.