VYPR
Low severity3.1NVD Advisory· Published Apr 1, 2025· Updated Jun 17, 2026

CVE-2025-3082

CVE-2025-3082

Description

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • MongoDB/MongoDB2 versions
    cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*range: >=5.0.0,<5.0.31
    • cpe:2.3:a:mongodb:mongodb:5.0.0:*:*:*:*:*:*:*range: 5.0
  • MongoDB/Serverllm-fuzzy
    Range: <5.0.31, <6.0.20, <7.0.14, <7.3.4
  • osv-coords
    Range: >= 5.0.0, < 5.0.31

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.