vulnerability
FreeBSD: VID-273c6c43-e3ad-11e9-8af7-08002720423d (CVE-2019-2389): mongodb -- Our init scripts check /proc/[pid]/stat should validate that `(${procname})` is the process' command name.
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 2 | (AV:L/AC:M/Au:N/C:N/I:N/A:P) | Sep 30, 2019 | Oct 12, 2019 | Jun 15, 2026 |
Severity
2
CVSS
(AV:L/AC:M/Au:N/C:N/I:N/A:P)
Published
Sep 30, 2019
Added
Oct 12, 2019
Modified
Jun 15, 2026
Description
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects MongoDB Server v4.0 versions prior to 4.0.11; MongoDB Server v3.6 versions prior to 3.6.14; MongoDB Server v3.4 versions prior to 3.4.22.
Solutions
freebsd-upgrade-package-mongodb34freebsd-upgrade-package-mongodb36freebsd-upgrade-package-mongodb40
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.