[Git][security-tracker-team/security-tracker][master] CVE-2020-7925/mongodb: not-affected

Sylvain Beucler beuc at debian.org
Sat Nov 28 08:39:33 GMT 2020



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8b86b868 by Sylvain Beucler at 2020-11-28T09:39:13+01:00
CVE-2020-7925/mongodb: not-affected

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -54202,7 +54202,10 @@ CVE-2020-7926 (A user authorized to perform database queries may cause denial of
 	NOTE: https://jira.mongodb.org/browse/SERVER-50170
 CVE-2020-7925 (Incorrect validation of user input in the role name parser may lead to ...)
 	- mongodb <removed>
+	[stretch] - mongodb <not-affected> (Vulnerable code introduced later)
 	NOTE: https://jira.mongodb.org/browse/SERVER-49142
+	NOTE: https://github.com/mongodb/mongo/commit/8fbd1af03310704de68c22163900636f58f7eba8 (v3.6.19)
+	NOTE: Introduced by: https://github.com/mongodb/mongo/commit/3ca76fd569c94de72c4daf6eef27fbf9bf51233b (v3.6.18)
 CVE-2020-7924
 	RESERVED
 CVE-2020-7923 (A user authorized to perform database queries may cause denial of serv ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b86b868ef979c8d54bd7fb2f1232440d9ee63b9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b86b868ef979c8d54bd7fb2f1232440d9ee63b9
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20201128/56d1a5d6/attachment.html>


More information about the debian-security-tracker-commits mailing list