Process termination via PID file manipulation
Vulnerability Description
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects MongoDB Server v4.0 versions prior to 4.0.11; MongoDB Server v3.6 versions prior to 3.6.14; MongoDB Server v3.4 versions prior to 3.4.22.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-2389
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Sicheng Liu of Beijing DBSEC Technology Co., Ltd
References
More from MongoDB Inc.
View All →Affected Vendor
MongoDB Inc.
View all reports →