Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2024-6376

Disclosure Date: July 01, 2024 (last updated July 04, 2024)
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2
Attacker Value
Unknown

CVE-2024-3371

Disclosure Date: April 24, 2024 (last updated February 07, 2025)
MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.
Attacker Value
Unknown

CVE-2023-37503

Disclosure Date: October 19, 2023 (last updated October 25, 2023)
HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.
Attacker Value
Unknown

CVE-2023-37504

Disclosure Date: October 19, 2023 (last updated October 25, 2023)
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user.
Attacker Value
Unknown

CVE-2023-37502

Disclosure Date: October 18, 2023 (last updated October 25, 2023)
HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server or by a user's web browser.
Attacker Value
Unknown

CVE-2023-39023

Disclosure Date: July 28, 2023 (last updated October 08, 2023)
university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument.
Attacker Value
Unknown

CVE-2023-27848

Disclosure Date: April 24, 2023 (last updated October 08, 2023)
broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
Attacker Value
Unknown

CVE-2022-42447

Disclosure Date: April 02, 2023 (last updated November 08, 2023)
HCL Compass is vulnerable to Cross-Origin Resource Sharing (CORS). This vulnerability can allow an unprivileged remote attacker to trick a legitimate user into accessing a special resource and executing a malicious request.
Attacker Value
Unknown

CVE-2022-30245

Disclosure Date: July 15, 2022 (last updated October 07, 2023)
Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote users. This enables configuration data to be stored on the controller and then implemented. A user with malicious intent can send a crafted packet to change the controller configuration without the knowledge of other users, altering the controller's function capabilities. The changed configuration is not updated in the User Interface, which creates an inconsistency between the configuration display and the actual configuration on the controller. After the configuration change, remediation requires reverting to the correct configuration, requiring either physical or remote access depending on the configuration that was altered.
Attacker Value
Unknown

CVE-2021-20334

Disclosure Date: April 06, 2021 (last updated February 22, 2025)
A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows.