MongoDB Compass < 1.39.1 Multiple Vulnerabilities

high Nessus Plugin ID 359479

Synopsis

An application installed on the remote host is affected by multiple vulnerabilities.

Description

The version of MongoDB Compass installed on the remote host is prior to 1.39.1. It is, therefore, affected by multiple vulnerabilities in the bundled Electron runtime, which was updated to version 23.3.12 in this release:

- Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (CVE-2023-3728)

- Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
(CVE-2023-3730)

- Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
(CVE-2023-3732)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to MongoDB Compass version 1.39.1 or later.

See Also

https://github.com/mongodb-js/compass/compare/v1.39.0...v1.39.1

https://www.mongodb.com/docs/compass/release-notes/

Plugin Details

Severity: High

ID: 359479

File Name: mongodb_compass_1_39_1.nasl

Version: 1.2

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 10/1/2026

Updated: 10/2/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-3732

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:mongodb:compass

Required KB Items: installed_sw/MongoDB Compass

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/8/2023

Vulnerability Publication Date: 8/1/2023

Reference Information

CVE: CVE-2023-3728, CVE-2023-3730, CVE-2023-3732