// For flags

CVE-2013-1892

MongoDB nativeHelper.apply Remote Code Execution

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

6
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.

MongoDB anterior a v2.0.9 y v2.2.x anterior a v.2.4 no valida correctamente las peticiones de la función nativeHelper en SpiderMonkey, lo que permite a usuarios autenticados remotamente provocar una denegación de servicio (acceso no válido a memoria y caída del servidor) o ejecutar código arbitrario a través una dirección de memoria manipulada en el primer argumento.

MongoDB is a NoSQL database. PyMongo provides tools for working with MongoDB. A flaw was found in the run() function implementation in MongoDB. A database user permitted to send database queries to a MongoDB server could use this flaw to crash the server or, possibly, execute arbitrary code with the privileges of the mongodb user. A NULL pointer dereference flaw was found in PyMongo. An invalid DBRef record received from a MongoDB server could cause an application using PyMongo to crash.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-02-19 CVE Reserved
  • 2013-04-02 CVE Published
  • 2013-04-02 First Exploit
  • 2024-08-06 CVE Updated
  • 2025-07-05 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-20: Improper Input Validation
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
<= 2.0.8
Search vendor "Mongodb" for product "Mongodb" and version " <= 2.0.8"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
1.2.0
Search vendor "Mongodb" for product "Mongodb" and version "1.2.0"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
1.4.0
Search vendor "Mongodb" for product "Mongodb" and version "1.4.0"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
1.6.0
Search vendor "Mongodb" for product "Mongodb" and version "1.6.0"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
1.8.0
Search vendor "Mongodb" for product "Mongodb" and version "1.8.0"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.0.0
Search vendor "Mongodb" for product "Mongodb" and version "2.0.0"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.0.1
Search vendor "Mongodb" for product "Mongodb" and version "2.0.1"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.0.2
Search vendor "Mongodb" for product "Mongodb" and version "2.0.2"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.0.3
Search vendor "Mongodb" for product "Mongodb" and version "2.0.3"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.0.4
Search vendor "Mongodb" for product "Mongodb" and version "2.0.4"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.0.5
Search vendor "Mongodb" for product "Mongodb" and version "2.0.5"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.0.6
Search vendor "Mongodb" for product "Mongodb" and version "2.0.6"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.0.7
Search vendor "Mongodb" for product "Mongodb" and version "2.0.7"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.2.0
Search vendor "Mongodb" for product "Mongodb" and version "2.2.0"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.2.1
Search vendor "Mongodb" for product "Mongodb" and version "2.2.1"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.2.2
Search vendor "Mongodb" for product "Mongodb" and version "2.2.2"
-
Affected
Mongodb
Search vendor "Mongodb"
Mongodb
Search vendor "Mongodb" for product "Mongodb"
2.2.3
Search vendor "Mongodb" for product "Mongodb" and version "2.2.3"
-
Affected
Redhat
Search vendor "Redhat"
Enterprise Mrg
Search vendor "Redhat" for product "Enterprise Mrg"
2.3
Search vendor "Redhat" for product "Enterprise Mrg" and version "2.3"
-
Affected