Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2024-6376
Disclosure Date: July 01, 2024 (last updated July 04, 2024)
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2
0
Attacker Value
Unknown
CVE-2024-3371
Disclosure Date: April 24, 2024 (last updated February 07, 2025)
MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.
0
Attacker Value
Unknown
CVE-2023-37503
Disclosure Date: October 19, 2023 (last updated October 25, 2023)
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
0
Attacker Value
Unknown
CVE-2023-37504
Disclosure Date: October 19, 2023 (last updated October 25, 2023)
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.
0
Attacker Value
Unknown
CVE-2023-37502
Disclosure Date: October 18, 2023 (last updated October 25, 2023)
HCL Compass is vulnerable to lack of file upload security. An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
0
Attacker Value
Unknown
CVE-2023-39023
Disclosure Date: July 28, 2023 (last updated October 08, 2023)
university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument.
0
Attacker Value
Unknown
CVE-2023-27848
Disclosure Date: April 24, 2023 (last updated October 08, 2023)
broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
0
Attacker Value
Unknown
CVE-2022-42447
Disclosure Date: April 02, 2023 (last updated November 08, 2023)
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.
0
Attacker Value
Unknown
CVE-2022-30245
Disclosure Date: July 15, 2022 (last updated October 07, 2023)
Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the knowledge of other users, altering the controller's function capabilities. The changed configuration is not updated in the User Interface, which creates an inconsistency between the configuration display and the actual configuration on the controller. After the configuration change, remediation requires reverting to the correct configuration, requiring either physical or remote access depending on the configuration that was altered.
0
Attacker Value
Unknown
CVE-2021-20334
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows.
0