← voltar
CVE-2025-14847

Zlib compressed protocol header length confusion may allow memory read

CVSS 8.7 HIGHEPSS 83.0%● KEVCWE-130
Em resumo

Servidores MongoDB com compressão Zlib possuem uma falha em que campos de comprimento desalinhados nos cabeçalhos permitem que atacantes não autenticados leiam memória não inicializada do servidor. Isso poderia expor dados sensíveis sem exigir autenticação.

Detalhe técnico

A vulnerabilidade existe na análise de cabeçalhos do protocolo comprimido Zlib, onde inconsistências nos campos de comprimento permitem que clientes remotos não autenticados disparem leituras de memória heap. Um atacante pode enviar mensagens de protocolo comprimido malformadas para vazar conteúdo de memória heap não inicializada, potencialmente expondo dados sensíveis, sem necessidade de autenticação.

Resumo gerado e traduzido por IA a partir da descrição oficial.
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
PoCs públicas encontradas41
githubgithub.com/Black1hp/mongobleed-scanner36githubgithub.com/cybertechajju/CVE-2025-14847_Expolit31githubgithub.com/ProbiusOfficial/CVE-2025-1484725githubgithub.com/onewinner/CVE-2025-1484714githubgithub.com/Security-Phoenix-demo/mongobleed-exploit-CVE-2025-1484713githubgithub.com/chinaxploiter/CVE-2025-14847-PoC4githubgithub.com/joshuavanderpoll/CVE-2025-148473githubgithub.com/franksec42/mongobleed-exploit-CVE-2025-148473githubgithub.com/peakcyber-security/CVE-2025-148472githubgithub.com/nma-io/mongobleed2githubgithub.com/alexcyberx/CVE-2025-14847_Expolit2githubgithub.com/lincemorado97/CVE-2025-148471githubgithub.com/sakthivel10q/CVE-2025-148471githubgithub.com/FurkanKAYAPINAR/CVE-2025-14847-MongoBleed-Exploit1githubgithub.com/NoNameError/MongoBLEED---CVE-2025-14847-POC-1githubgithub.com/waheeb71/CVE-2025-148471githubgithub.com/CadGoose/MongoBleed-CVE-2025-14847-Fully-Automated-scanner1githubgithub.com/AdolfBharath/mongobleed1githubgithub.com/InfoSecAntara/CVE-2025-14847-MongoDB1githubgithub.com/dawnsmithcyber/azure-vulnerability-remediation-project1githubgithub.com/amnnrth/CVE-2025-148470githubgithub.com/Rishi-kaul/CVE-2025-14847-MongoBleed0githubgithub.com/Systemhaus-Schulz/MongoBleed-CVE-2025-148470githubgithub.com/ElJoamy/MongoBleed-exploit0githubgithub.com/keraattin/Mongobleed-Detector-CVE-2025-148470githubgithub.com/shokribardiya/CVE-2025-14847-mongobleed0githubgithub.com/sho-luv/MongoBleed0githubgithub.com/im-hanzou/mongobleed0githubgithub.com/0xBlackash/CVE-2025-148470githubgithub.com/sahar042/CVE-2025-148470githubgithub.com/saereya/CVE-2025-14847---MongoBleed0githubgithub.com/KingHacker353/CVE-2025-14847_Expolit0githubgithub.com/pedrocruz2202/mongobleed-scanner0githubgithub.com/pedrocruz2202/pedrocruz2202.github.io0githubgithub.com/14mb1v45h/CYBERDUDEBIVASH-MONGODB-DETECTOR-v20260githubgithub.com/kuyrathdaro/cve-2025-148470githubgithub.com/JemHadar/MongoBleed-DFIR-Triage-Script-CVE-2025-148470githubgithub.com/tunahantekeoglu/MongoDeepDive0githubgithub.com/vfa-tuannt/CVE-2025-148470githubgithub.com/j0lt-github/mongobleedburp0githubgithub.com/sakthivel10q/sakthivel10q.github.io0
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →