Posts

Showing posts with the label infosec

The Hacker News

Image
"New Mongo DB flaw lets unauthorized attackers read uninitialized memory." Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 28 December 2025, 2217 UTC. Content and Source:  "The Hacker News." URL--https://thehackernews.com/ Please check URL or scroll down to read your selections.  Thanks for joining us today. Russ Roberts (https://www.hawaiicybersecurityjournal.net).   New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory  Dec 27, 2025 Database Security / Vulnerability A high-severity security flaw has been disclosed in MongoDB that could allow unauthenticated users to read uninitialized heap memory. The vulnerability, tracked as CVE-2025-14847 (CVSS score: 8.7), has been described as a case of improper handling of length parameter inconsistency , which arises when a program fails to appropriately tackle scenarios where a length field is inconsistent with the actual length of t...