CVE-2022-48282

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-48282
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48282.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-48282
Aliases
Withdrawn
2024-05-15T05:32:10.844203Z
Published
2023-02-21T19:15:10Z
Modified
2023-11-29T10:00:33.991607Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which may cause further disruption to services. This is specific to applications written in C#. This affects all MongoDB .NET/C# Driver versions prior to and including v2.18.0

Following configuration must be true for the vulnerability to be applicable: * Application must written in C# taking arbitrary data from users and serializing data using _t without any validation AND * Application must be running on a Windows host using the full .NET Framework, not .NET Core AND * Application must have domain model class with a property/field explicitly of type System.Object or a collection of type System.Object (against MongoDB best practice) AND * Malicious attacker must have unrestricted insert access to target database to add a _t discriminator."Following configuration must be true for the vulnerability to be applicable

References

Affected packages

Git / github.com/mongodb/mongo-csharp-driver

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo-csharp-driver
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.11.0.4042
v0.5.0.3940
v0.7.0.3959
v0.9.0.3992

v1.*

v1.0.0.4098
v1.1.0.4184
v1.2.0.4274
v1.3.0.4309
v1.4.0.4468
v1.4.1.4490
v1.4.2.4500
v1.5.0.4566
v1.6.0.4624
v1.6.0rc0
v1.6.1.4678
v1.7.0.4714
v1.8.0.124
v1.8.1.20
v1.8.2.34
v1.9.0
v1.9.0-rc0
v1.9.0-rc1

v2.*

v2.0.0
v2.0.0-beta1
v2.0.0-beta2
v2.0.0-beta3
v2.0.0-beta4
v2.0.0-rc0
v2.1.0-rc0
v2.1.0-rc1
v2.10.0
v2.10.0-beta1
v2.11.0
v2.11.0-beta1
v2.11.0-beta2
v2.12.0
v2.12.0-beta1
v2.13.0
v2.13.0-beta1
v2.14.0
v2.14.0-beta1
v2.15.0
v2.16.0
v2.17.0
v2.18.0
v2.2.0
v2.2.0-rc0
v2.2.1
v2.3.0
v2.3.0-beta1
v2.3.0-rc1
v2.4.0
v2.4.0-beta1
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.5.0
v2.7.0
v2.7.0-beta1
v2.9.0
v2.9.0-beta1
v2.9.0-beta2
v2.9.1