MongoBleed CVE-2025-14847: Why This MongoDB Memory Leak Is Worse Than RCE
Автор: Phoenix Security
Загружено: 2025-12-30
Просмотров: 44059
MongoBleed (CVE-2025-14847) is an unauthenticated MongoDB memory disclosure caused by a zlib compression bug. In this video, we break down the exact code flaw, show how memory leaks turn into RCE-adjacent attacks, and explain what security teams must do to respond.
Timestamps (chapters):
00:00 What is MongoBleed and why it matters
00:38 Why this is not RCE (but still critical)
01:15 Internet exposure: 87,000+ MongoDB instances
02:05 Root cause: the zlib decompression bug
03:10 How the vulnerable code leaks memory
04:20 From memory leak to cloud compromise
05:25 What attackers steal from heap memory
06:25 How to fix MongoBleed (patching and mitigations)
07:10 Final takeaways
A full technical deep dive, affected versions, and mitigation guidance are available in the linked blog post - https://phoenix.security/mongobleed-v...
#aspm #applicationsecurity #vulnerabilitymanagement #MongoDB #CVE_2025_4847 #MongoBleed #devsecops
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: