Search found 2 matches

by rmatulka
Thu Mar 12, 2026 11:48 am
Forum: Bug reporting
Topic: Embedded MongoDB 6.0.3 vulnerability in WebInterface
Replies: 3
Views: 361

Embedded MongoDB 6.0.3 vulnerability in WebInterface

Hi, CrowdStrike recently flagged a vulnerability related to MongoDB 6.0.3 (e.g. MongoBleed / CVE-2025-14847) on a server running FFAStrans WebInterface. In our setup the WebInterface server.exe starts an internal mongod process which listens only on 127.0.0.1:8010 (localhost). Because the database i...