
Explot, Lab, Scanner - container esterno e docker, per SMongobleed-CVE-2025-14847 più phoenix security uploader
CVE-2025-14847 | CVSS 8.7 (Alto) | Divulgazione di memoria non autenticata
CVE-2025-14847, soprannominata MongoBleed, consente ad attaccanti remoti non autenticati di esfiltrare memoria heap non inizializzata sfruttando la logica di decompressione zlib di MongoDB. Questo difetto ad alta gravità espone artefatti sensibili, tra cui credenziali in chiaro e token di sessione, fornendo una mappa per il movimento laterale e la completa compromissione del server.
| Aspetto | Dettagli |
|---|---|
| Cosa è vulnerabile | Livello di trasporto di rete del server MongoDB che utilizza la compressione zlib |
| Gravità | Alta (CVSS 8.7/7.5) |
| Impatto | Divulgazione remota non autenticata di memoria heap non inizializzata |
| Perché è importante | I frammenti divulgati contengono password di database, chiavi segrete AWS e stati interni del server |
| Stato dell'exploit | Il Proof-of-Concept (PoC) pubblico "mongobleed" è validato e in circolazione |
| Cosa fare oggi | Aggiornare immediatamente alle versioni patchate o disabilitare la compressione zlib |
La vulnerabilità risiede nel livello di trasporto di rete di MongoDB (message_compressor_zlib.cpp), dove un difetto critico nella logica di decompressione zlib consente ad attaccanti non autenticati di divulgare memoria sensibile del server.
// VULNERABLE CODE (before fix)
counterHitDecompress(input.length(), output.length());
return {output.length()}; // ❌ Returns ALLOCATED buffer size
// PATCHED CODE (after fix)
counterHitDecompress(input.length(), output.length());
return length; // ✅ Returns ACTUAL decompressed data length
┌─────────────────────────────────────────────────────────────────────────────┐
│ MongoBleed Attack Vector │
├─────────────────────────────────────────────────────────────────────────────┤
│ │
│ ATTACKER VULNERABLE MongoDB │
│ │ │ │
│ │ 1. Send OP_COMPRESSED message │ │
│ │ uncompressedSize: 8192 (LIE) │ │
│ │ actual data: ~100 bytes │ │
│ │────────────────────────────────────> │
│ │ │ │
│ │ 2. Allocate 8192-byte buffer │
│ │ 3. Decompress ~100 bytes │
│ │ 4. BUG: Return buffer.length() = 8192 │
│ │ 5. BSON parser reads uninitialized memory │
│ │ │ │
│ │ 6. Error response with leaked │ │
│ │ memory as "field names" │ │
│ │<──────────────────────────────────── │
│ │ │ │
│ 🔓 LEAKED DATA: │ │
│ - API keys, passwords, tokens │
│ - MongoDB internal state │
│ - WiredTiger storage configs │
│ - System /proc information │
│ - Client connection data │
│ │
└─────────────────────────────────────────────────────────────────────────────┘
| Versione | Intervallo vulnerabile | Versione corretta | Stato |
|---|---|---|---|
| 8.2.x | 8.2.0 - 8.2.2 | 8.2.3 | ✅ Patchata |
| 8.0.x | 8.0.0 - 8.0.16 | 8.0.17 | ✅ Patchata |
| 7.0.x | 7.0.0 - 7.0.27 | 7.0.28 | ✅ Patchata |
| 6.0.x | 6.0.0 - 6.0.26 | 6.0.27 | ✅ Patchata |
| 5.0.x | 5.0.0 - 5.0.31 | 5.0.32 | ✅ Patchata |
| 4.4.x | 4.4.0 - 4.4.29 | 4.4.30 | ✅ Patchata |
| 4.2.x | Tutte le versioni | Nessuna | ⚠️ EOL |
| 4.0.x | Tutte le versioni | Nessuna | ⚠️ EOL |
| 3.6.x | Tutte le versioni | Nessuna | ⚠️ EOL |
| Data | Evento |
|---|---|
| 15 dicembre 2025 | Vulnerabilità identificata; ticket interno SERVER-115508 |
| 19 dicembre 2025 | Patch rilasciata, CVE-2025-14847 pubblicata |
| 24 dicembre 2025 | Flotta MongoDB Atlas patchata |
| 26 dicembre 2025 | PoC pubblico "mongobleed" rilasciato |
| 28 dicembre 2025 | Sfruttamento osservato in natura |
mongobleed-exploit-CVE-2025-14847/
├── exploit/ # 🔴 Exploit Lab
│ ├── docker-compose.yml # Vulnerable + Patched MongoDB instances
│ ├── mongobleed.py # Memory leak exploit PoC
│ ├── init/init-mongo.js # Sensitive test data
│ ├── test-exploit.sh # Lab test script
│ └── README.md # Lab documentation
│
├── scanner/ # 🌐 Network Scanner
│ ├── mongobleed_scanner.py # IP/domain vulnerability scanner
│ ├── sample-targets.txt # Sample targets file
│ └── README.md # Scanner documentation
│
├── code-scan/ # 📂 Code Scanner
│ ├── main.py # CLI entry point
│ ├── scanners/ # Docker, Python, Infra scanners
│ ├── models/ # Finding, Vulnerability models
│ ├── integrations/ # Phoenix Security upload
│ └── README.md # Code scanner documentation
│
└── original-exploit/ # 📚 Original PoC reference
cd exploit
# Start lab (vulnerable + patched instances)
docker-compose up -d
sleep 10
# Test vulnerable instance (should leak memory)
python3 mongobleed.py --host localhost --port 27017
# Test patched instance (should NOT leak memory)
python3 mongobleed.py --host localhost --port 27018
# Full lab test
./test-exploit.sh
cd scanner
# Scan single host
python3 mongobleed_scanner.py 192.168.1.100
# Scan network range
python3 mongobleed_scanner.py 192.168.1.0/24
# Scan from file
python3 mongobleed_scanner.py @sample-targets.txt --json --output results.json
cd code-scan
# Scan project for vulnerable MongoDB versions
python3 main.py scan /path/to/project
# Scan and upload to Phoenix
python3 main.py scan /path/to/project --upload-phoenix
# Run tests
python3 main.py test
# === EXPLOIT LAB ===
# Start lab
cd exploit && docker-compose up -d && sleep 10
# Run exploit (vulnerable instance)
python3 exploit/mongobleed.py --host localhost --port 27017