Skip to content
KitploitKITPLOIT
ツールブログ
Log in
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

フィードお問い合わせプライバシー© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
mongobleed-exploit-CVE-2025-14847 — Explot、Lab、Scanner - 外部およびDockerコンテナ、SMongobleed-CVE-2025-14847およびphoenix security uploader用 | Kitploit
ツール/GitHubGitHub/franksec42/mongobleed-exploit-cve-2025-14847
コンテナセキュリティメモリフォレンジック脆弱性分析エクスプロイトペネトレーションテストクラウドセキュリティ学習と教育データベースセキュリティラボと実践

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有
GitHubfranksec42/mongobleed-exploit-cve-2025-14847

mongobleed-exploit-CVE-2025-14847

Explot、Lab、Scanner - 外部およびDockerコンテナ、SMongobleed-CVE-2025-14847およびphoenix security uploader用

リポジトリを見る
31157ヶ月前未レビュー

🩸 MongoBleed - CVE-2025-14847 セキュリティ研究ラボ

MongoBleed ロゴ

CVE-2025-14847 | CVSS 8.7 (High) | 認証なしメモリ開示


CVE-2025-14847 は MongoBleed と呼ばれ、MongoDB の zlib 伸張ロジックを悪用することで、認証されていないリモート攻撃者が初期化されていないヒープメモリを漏えいさせることを可能にします。この高深刻度の脆弱性は、平文の認証情報やセッショントークンなどの機密情報を露出させ、横展開とサーバー完全乗っ取りへのロードマップを提供します。

📖 完全なドキュメント →


エンジニア向け TL;DR

項目詳細
脆弱なものzlib圧縮を使用する MongoDB Server のネットワーク転送層
深刻度High (CVSS 8.7/7.5)
影響認証なしでの、初期化されていないヒープメモリのリモート開示
重要視される理由漏えいした断片には、データベースのパスワード、AWSシークレットキー、内部サーバー状態が含まれる
エクスプロイト状況パブリックな Proof-of-Concept (PoC) "mongobleed" が検証され、流通している
今日やるべきことパッチ適用済みバージョンに直ちにアップグレードするか、zlib圧縮を無効化する

暴露規模

  • 87,000 ~ 194,000 の MongoDB インスタンスが公開曝露
  • 42% のクラウド環境が影響 (Wiz Research)
  • 認証不要 - 事前認証でエクスプロイト可能

🔬 脆弱性の構造

技術的分析

この脆弱性は MongoDB のネットワーク転送層 (message_compressor_zlib.cpp) に存在し、zlib 伸張ロジックの重大な欠陥により、認証されていない攻撃者がサーバーの機密メモリを漏えいさせることができます。

根本原因

// VULNERABLE CODE (before fix)
counterHitDecompress(input.length(), output.length());
return {output.length()};  // ❌ Returns ALLOCATED buffer size

// PATCHED CODE (after fix)  
counterHitDecompress(input.length(), output.length());
return length;             // ✅ Returns ACTUAL decompressed data length

エクスプロイトの流れ

┌─────────────────────────────────────────────────────────────────────────────┐
│                        MongoBleed Attack Vector                             │
├─────────────────────────────────────────────────────────────────────────────┤
│                                                                              │
│   ATTACKER                         VULNERABLE MongoDB                        │
│      │                                    │                                  │
│      │  1. Send OP_COMPRESSED message     │                                  │
│      │     uncompressedSize: 8192 (LIE)   │                                  │
│      │     actual data: ~100 bytes        │                                  │
│      │────────────────────────────────────>                                  │
│      │                                    │                                  │
│      │                          2. Allocate 8192-byte buffer                 │
│      │                          3. Decompress ~100 bytes                     │
│      │                          4. BUG: Return buffer.length() = 8192        │
│      │                          5. BSON parser reads uninitialized memory    │
│      │                                    │                                  │
│      │  6. Error response with leaked     │                                  │
│      │     memory as "field names"        │                                  │
│      │<────────────────────────────────────                                  │
│      │                                    │                                  │
│   🔓 LEAKED DATA:                         │                                  │
│      - API keys, passwords, tokens                                           │
│      - MongoDB internal state                                                │
│      - WiredTiger storage configs                                            │
│      - System /proc information                                              │
│      - Client connection data                                                │
│                                                                              │
└─────────────────────────────────────────────────────────────────────────────┘

影響を受けるバージョン

バージョン脆弱な範囲修正バージョンステータス
8.2.x8.2.0 - 8.2.28.2.3✅ パッチ済み
8.0.x8.0.0 - 8.0.168.0.17✅ パッチ済み
7.0.x7.0.0 - 7.0.277.0.28✅ パッチ済み
6.0.x6.0.0 - 6.0.266.0.27✅ パッチ済み
5.0.x5.0.0 - 5.0.315.0.32✅ パッチ済み
4.4.x4.4.0 - 4.4.294.4.30✅ パッチ済み
4.2.x全バージョンなし⚠️ サポート終了
4.0.x全バージョンなし⚠️ サポート終了
3.6.x全バージョンなし⚠️ サポート終了

発見のタイムライン

日付イベント
2025年12月15日脆弱性を特定、内部チケット SERVER-115508
2025年12月19日修正をリリース、CVE-2025-14847 を公開
2025年12月24日MongoDB Atlas フリートにパッチ適用
2025年12月26日パブリック PoC "mongobleed" を公開
2025年12月28日実環境での悪用を確認

📁 プロジェクト構成

mongobleed-exploit-CVE-2025-14847/
├── exploit/                    # 🔴 Exploit Lab
│   ├── docker-compose.yml      # Vulnerable + Patched MongoDB instances
│   ├── mongobleed.py           # Memory leak exploit PoC
│   ├── init/init-mongo.js      # Sensitive test data
│   ├── test-exploit.sh         # Lab test script
│   └── README.md               # Lab documentation
│
├── scanner/                    # 🌐 Network Scanner
│   ├── mongobleed_scanner.py   # IP/domain vulnerability scanner
│   ├── sample-targets.txt      # Sample targets file
│   └── README.md               # Scanner documentation
│
├── code-scan/                  # 📂 Code Scanner
│   ├── main.py                 # CLI entry point
│   ├── scanners/               # Docker, Python, Infra scanners
│   ├── models/                 # Finding, Vulnerability models
│   ├── integrations/           # Phoenix Security upload
│   └── README.md               # Code scanner documentation
│
└── original-exploit/           # 📚 Original PoC reference

🚀 クイックスタート

1. エクスプロイトラボ

cd exploit

# Start lab (vulnerable + patched instances)
docker-compose up -d
sleep 10

# Test vulnerable instance (should leak memory)
python3 mongobleed.py --host localhost --port 27017

# Test patched instance (should NOT leak memory)
python3 mongobleed.py --host localhost --port 27018

# Full lab test
./test-exploit.sh

2. ネットワークスキャナー

cd scanner

# Scan single host
python3 mongobleed_scanner.py 192.168.1.100

# Scan network range
python3 mongobleed_scanner.py 192.168.1.0/24

# Scan from file
python3 mongobleed_scanner.py @sample-targets.txt --json --output results.json

3. コードスキャナー

cd code-scan

# Scan project for vulnerable MongoDB versions
python3 main.py scan /path/to/project

# Scan and upload to Phoenix
python3 main.py scan /path/to/project --upload-phoenix

# Run tests
python3 main.py test

⚡ クイックコマンド

# === EXPLOIT LAB ===
# Start lab
cd exploit && docker-compose up -d && sleep 10

# Run exploit (vulnerable instance)
python3 exploit/mongobleed.py --host localhost --port 27017

# Run exploit (patched instance - verify no leaks)
python3 exploit/mongobleed.py --host localhost --port 27018

# === NETWORK SCANNER ===
# Scan local lab
python3 scanner/mongobleed_scanner.py localhost:27017 localhost:27018

# Scan network
python3 scanner/mongobleed_scanner.py 192.168.1.0/24 --threads 20

# === CODE SCANNER ===
# Scan current directory
python3 code-scan/main.py scan .

# Scan with JSON output
python3 code-scan/main.py scan /path/to/project --json --output results.json

# Scan and upload to Phoenix
python3 code-scan/main.py scan /path/to/project --upload-phoenix

📊 出力例

エクスプロイト出力

[*] mongobleed - CVE-2025-14847 MongoDB Memory Leak
[*] Target: localhost:27017
[*] Scanning offsets 20-8192...

[+] offset=  117 len=  39: ssions^\u0001�r��*YDr���
[+] offset=16582 len=1552: MemAvailable:    8554792 kB\nBuffers: ...
[+] offset=18731 len=3908: MONGOBLEED_PRIVATE_KEY_DATA_123...

[!] TARGET IS VULNERABLE TO CVE-2025-14847
[*] Total leaked: 8748 bytes
[*] Unique fragments: 42

[!] Potential secrets detected:
    • RSA Private Key
    • Lab Secret

ネットワークスキャナー出力

ツールをダウンロード