
Explot, Lab, Scanner - externo y contenedor docker, para SMongobleed-CVE-2025-14847 más phoenix security uploader
CVE-2025-14847 | CVSS 8.7 (Alto) | Divulgación de Memoria No Autenticada
CVE-2025-14847, apodado MongoBleed, permite a atacantes remotos no autenticados extraer memoria heap no inicializada explotando la lógica de descompresión zlib de MongoDB. Esta falla de alta gravedad expone artefactos sensibles, incluyendo credenciales en texto plano y tokens de sesión, proporcionando una hoja de ruta para movimiento lateral y toma completa del servidor.
| Aspecto | Detalles |
|---|---|
| Qué es vulnerable | Capa de transporte de red del servidor MongoDB que utiliza compresión zlib |
| Gravedad | Alta (CVSS 8.7/7.5) |
| Impacto | Divulgación remota no autenticada de memoria heap no inicializada |
| Por qué es importante | Los fragmentos filtrados contienen contraseñas de bases de datos, claves secretas de AWS y estados internos del servidor |
| Estado del exploit | Prueba de concepto (PoC) pública "mongobleed" está validada y circulando |
| Qué hacer hoy | Actualice a versiones parcheadas inmediatamente o deshabilite la compresión zlib |
La vulnerabilidad existe en la capa de transporte de red de MongoDB (message_compressor_zlib.cpp) donde una falla crítica en la lógica de descompresión zlib permite a atacantes no autenticados filtrar memoria sensible del servidor.
// VULNERABLE CODE (before fix)
counterHitDecompress(input.length(), output.length());
return {output.length()}; // ❌ Returns ALLOCATED buffer size
// PATCHED CODE (after fix)
counterHitDecompress(input.length(), output.length());
return length; // ✅ Returns ACTUAL decompressed data length
┌─────────────────────────────────────────────────────────────────────────────┐
│ MongoBleed Attack Vector │
├─────────────────────────────────────────────────────────────────────────────┤
│ │
│ ATTACKER VULNERABLE MongoDB │
│ │ │ │
│ │ 1. Send OP_COMPRESSED message │ │
│ │ uncompressedSize: 8192 (LIE) │ │
│ │ actual data: ~100 bytes │ │
│ │────────────────────────────────────> │
│ │ │ │
│ │ 2. Allocate 8192-byte buffer │
│ │ 3. Decompress ~100 bytes │
│ │ 4. BUG: Return buffer.length() = 8192 │
│ │ 5. BSON parser reads uninitialized memory │
│ │ │ │
│ │ 6. Error response with leaked │ │
│ │ memory as "field names" │ │
│ │<──────────────────────────────────── │
│ │ │ │
│ 🔓 LEAKED DATA: │ │
│ - API keys, passwords, tokens │
│ - MongoDB internal state │
│ - WiredTiger storage configs │
│ - System /proc information │
│ - Client connection data │
│ │
└─────────────────────────────────────────────────────────────────────────────┘
| Versión | Rango Vulnerable | Versión Corregida | Estado |
|---|---|---|---|
| 8.2.x | 8.2.0 - 8.2.2 | 8.2.3 | ✅ Parcheado |
| 8.0.x | 8.0.0 - 8.0.16 | 8.0.17 | ✅ Parcheado |
| 7.0.x | 7.0.0 - 7.0.27 | 7.0.28 | ✅ Parcheado |
| 6.0.x | 6.0.0 - 6.0.26 | 6.0.27 | ✅ Parcheado |
| 5.0.x | 5.0.0 - 5.0.31 | 5.0.32 | ✅ Parcheado |
| 4.4.x | 4.4.0 - 4.4.29 | 4.4.30 | ✅ Parcheado |
| 4.2.x | Todas las versiones | Ninguna | ⚠️ EOL |
| 4.0.x | Todas las versiones | Ninguna | ⚠️ EOL |
| 3.6.x | Todas las versiones | Ninguna | ⚠️ EOL |
| Fecha | Evento |
|---|---|
| 15 Dic 2025 | Vulnerabilidad identificada; ticket interno SERVER-115508 |
| 19 Dic 2025 | Corrección publicada, CVE-2025-14847 divulgado |
| 24 Dic 2025 | Flota de MongoDB Atlas parcheada |
| 26 Dic 2025 | PoC pública "mongobleed" publicada |
| 28 Dic 2025 | Explotación observada en la naturaleza |
mongobleed-exploit-CVE-2025-14847/
├── exploit/ # 🔴 Exploit Lab
│ ├── docker-compose.yml # Vulnerable + Patched MongoDB instances
│ ├── mongobleed.py # Memory leak exploit PoC
│ ├── init/init-mongo.js # Sensitive test data
│ ├── test-exploit.sh # Lab test script
│ └── README.md # Lab documentation
│
├── scanner/ # 🌐 Network Scanner
│ ├── mongobleed_scanner.py # IP/domain vulnerability scanner
│ ├── sample-targets.txt # Sample targets file
│ └── README.md # Scanner documentation
│
├── code-scan/ # 📂 Code Scanner
│ ├── main.py # CLI entry point
│ ├── scanners/ # Docker, Python, Infra scanners
│ ├── models/ # Finding, Vulnerability models
│ ├── integrations/ # Phoenix Security upload
│ └── README.md # Code scanner documentation
│
└── original-exploit/ # 📚 Original PoC reference
cd exploit
# Start lab (vulnerable + patched instances)
docker-compose up -d
sleep 10
# Test vulnerable instance (should leak memory)
python3 mongobleed.py --host localhost --port 27017
# Test patched instance (should NOT leak memory)
python3 mongobleed.py --host localhost --port 27018
# Full lab test
./test-exploit.sh
cd scanner
# Scan single host
python3 mongobleed_scanner.py 192.168.1.100
# Scan network range
python3 mongobleed_scanner.py 192.168.1.0/24
# Scan from file
python3 mongobleed_scanner.py @sample-targets.txt --json --output results.json
cd code-scan
# Scan project for vulnerable MongoDB versions
python3 main.py scan /path/to/project
# Scan and upload to Phoenix
python3 main.py scan /path/to/project --upload-phoenix
# Run tests
python3 main.py test
# === EXPLOIT LAB ===
# Start lab
cd exploit && docker-compose up -d && sleep 10
# Run exploit (vulnerable instance)
python3 exploit/mongobleed.py --host localhost --port 27017