Tag

Cve 2025 14847

All articles tagged with #cve 2025 14847

Active Exploitation of Critical MongoDB Vulnerability CVE-2025-14847
database-security1 month ago

Active Exploitation of Critical MongoDB Vulnerability CVE-2025-14847

A critical vulnerability in MongoDB, CVE-2025-14847, allows unauthenticated attackers to remotely leak sensitive data by exploiting a flaw in zlib compression, with over 87,000 instances potentially affected worldwide. Users are advised to update their MongoDB versions and implement mitigations such as disabling zlib compression and restricting server exposure.

MongoBleed Vulnerability in MongoDB Now Actively Exploited in the Wild
technology2 months ago

MongoBleed Vulnerability in MongoDB Now Actively Exploited in the Wild

A critical security flaw called MongoBleed (CVE-2025-14847) in MongoDB servers is actively exploited in the wild, allowing attackers to leak sensitive data through malformed network packets before authentication, affecting many versions and exposing approximately 87,000 vulnerable instances worldwide. Immediate patching and monitoring are recommended.

MongoBleed Vulnerability Exposes Over 87,000 MongoDB Instances to Exploits
technology2 months ago

MongoBleed Vulnerability Exposes Over 87,000 MongoDB Instances to Exploits

A critical vulnerability named MongoBleed (CVE-2025-14847) affects over 87,000 MongoDB instances by allowing unauthenticated remote attackers to extract sensitive data through uninitialized memory disclosure in zlib decompression. The flaw impacts multiple versions, with patches available, and a PoC exploit has been released, increasing the risk of active exploitation. Administrators are urged to update their systems or apply temporary mitigations such as disabling zlib compression and restricting network access.

MongoDB Urges Immediate Patch for Critical RCE and Data Leak Vulnerabilities
technology2 months ago

MongoDB Urges Immediate Patch for Critical RCE and Data Leak Vulnerabilities

MongoDB has issued an urgent warning to patch a severe remote code execution vulnerability (CVE-2025-14847) affecting multiple versions of its database software. The flaw, due to improper handling of length parameters, allows unauthenticated attackers to execute arbitrary code. Admins are advised to upgrade to patched versions immediately or disable zlib compression to mitigate the risk. The vulnerability has been actively exploited in the past, emphasizing the need for prompt action.