{"id":372,"date":"2025-09-28T18:04:07","date_gmt":"2025-09-28T18:04:07","guid":{"rendered":"https:\/\/aldomonges.com\/aldomonges\/?p=372"},"modified":"2025-09-28T18:04:07","modified_gmt":"2025-09-28T18:04:07","slug":"vulnerabilidad-en-mongodb","status":"publish","type":"post","link":"https:\/\/aldomonges.com\/aldomonges\/?p=372","title":{"rendered":"Vulnerabilidad en MongoDB"},"content":{"rendered":"<p>Se ha descubierto una vulnerabilidad de severidad alta en MongoDB. Un actor malicioso podr\u00eda lograr la ejecuci\u00f3n remota de c\u00f3digo.<\/p>\n<p><strong>Producto<\/strong><strong>s a<\/strong><strong>fectado<\/strong><strong>s<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>MongoDB Server v6.0, versiones anteriores a 6.0.25.<\/li>\n<li>MongoDB Server v7.0, versiones anteriores a 7.0.21.<\/li>\n<li>MongoDB Server v8.0, versiones anteriores a 8.0.5.<\/li>\n<\/ul>\n<p><strong>Impacto<\/strong><\/p>\n<p><strong>La vulnerabilidad se ha identificado como:<\/strong><\/p>\n<p><strong>CVE-2025-<\/strong><strong>10491<\/strong><strong>:\u00a0<\/strong>con una puntuaci\u00f3n de 7.8 en CVSS v3.1. El instalador MSI de MongoDB en Windows podr\u00eda dejar listas de control de acceso (ACL) no definidas en directorios de instalaci\u00f3n personalizados. Un actor malicioso podr\u00eda introducir c\u00f3digo ejecutable a trav\u00e9s de DLL hijacking.<\/p>\n<p><strong>Recomendaci\u00f3n<\/strong><\/p>\n<p>Actualizar a la \u00faltima versi\u00f3n disponible a trav\u00e9s del sitio web oficial del fabricante.<\/p>\n<p><strong>Referencias<\/strong><\/p>\n<ul class=\"wp-block-list\">\n<li>https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-10491<\/li>\n<li>https:\/\/jira.mongodb.org\/browse\/SERVER-106749?jql=project%20%3D%20SERVER%20AND%20fixVersion%20%3D%208.1.0-rc0<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Se ha descubierto una vulnerabilidad de severidad alta en MongoDB. Un actor malicioso podr\u00eda lograr la ejecuci\u00f3n remota de c\u00f3digo. Productos afectados MongoDB Server v6.0, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":373,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-372","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-seguridad-informatica"],"jetpack_featured_media_url":"https:\/\/i3.wp.com\/www.developer-tech.com\/wp-content\/uploads\/2021\/02\/mongodb-atlas-google-cloud-partnership-nosql-databases-integrations-2.jpg?w=1470&resize=1470,885&ssl=1","_links":{"self":[{"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=\/wp\/v2\/posts\/372","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=372"}],"version-history":[{"count":1,"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=\/wp\/v2\/posts\/372\/revisions"}],"predecessor-version":[{"id":374,"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=\/wp\/v2\/posts\/372\/revisions\/374"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=\/wp\/v2\/media\/373"}],"wp:attachment":[{"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=372"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=372"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aldomonges.com\/aldomonges\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}