>Dubbed MongoBleed by the Elastic Security researcher who published a proof of concept on December 26, the vulnerability was actually identified back on December 15 and patched by the MongoDB crew shortly thereafter. It affects a wide range of MongoDB Server versions, with MongoDB urging affected users to upgrade to fixed releases immediately.
>“If you cannot upgrade immediately, disable zlib compression on the MongoDB Server,“ the MongoDB maker urged.
So no big deal.
Leave A Reply
Du musst angemeldet sein, um einen Kommentar abzugeben.
1 Kommentar
>Dubbed MongoBleed by the Elastic Security researcher who published a proof of concept on December 26, the vulnerability was actually identified back on December 15 and patched by the MongoDB crew shortly thereafter. It affects a wide range of MongoDB Server versions, with MongoDB urging affected users to upgrade to fixed releases immediately.
>“If you cannot upgrade immediately, disable zlib compression on the MongoDB Server,“ the MongoDB maker urged.
So no big deal.