Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day. Here’s said exploit: GitHub - joe-desimone/mongobleed The vuln, which dropped just before Christmas, in theory allowed memory read without authentication. Patches are available. It impacts every version of MongoDB going back about a decade. Another vendor decided it would be a great idea to post technical details on Christmas Eve: ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-202
评论
?
参与讨论