UNCLASSIFIED - NO CUI

Skip to content

chore(findings): mongodb/mongodb-enterprise/mongodb-agent

Summary

mongodb/mongodb-enterprise/mongodb-agent has 196 new findings discovered during continuous monitoring.

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=mongodb/mongodb-enterprise/mongodb-agent&tag=108.0.12.8846-1&branch=master

EPSS (Exploit Prediction Scoring System) provides an estimate of the likelihood that a vulnerability will be exploited in the wild.

KEV (Known Exploited Vulnerabilities) indicates whether a vulnerability is actively being exploited according to CISA.

id source severity package impact workaround epss_score kev
CVE-2023-2650 Anchore CVE Medium openssl-1:1.1.1k-14.el8_6 0.88208 false
CVE-2020-19188 Anchore CVE Low ncurses-6.1-10.20180224.el8 0.06200 false
CVE-2020-19186 Anchore CVE Low ncurses-6.1-10.20180224.el8 0.04961 false
CVE-2020-19185 Anchore CVE Low ncurses-6.1-10.20180224.el8 0.04961 false
CVE-2020-19190 Anchore CVE Low ncurses-6.1-10.20180224.el8 0.04954 false
CVE-2020-19187 Anchore CVE Low ncurses-6.1-10.20180224.el8 0.04834 false
CVE-2022-23990 Anchore CVE Medium expat-2.2.5-17.el8_10 0.03519 false
CVE-2005-2541 Anchore CVE Medium tar-2:1.30-11.el8_10 0.03250 false
CVE-2020-20703 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.02806 false
CVE-2020-19189 Anchore CVE Low ncurses-6.1-10.20180224.el8 0.02005 false
CVE-2024-2511 Anchore CVE Low openssl-1:1.1.1k-14.el8_6 0.01519 false
CVE-2022-2182 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.01439 false
CVE-2019-9674 Twistlock CVE Low python3-3.6.8-71.el8_10 0.01198 false
CVE-2019-9674 Anchore CVE Low platform-python-3.6.8-71.el8_10 0.01198 false
CVE-2019-9674 Anchore CVE Low python3-libs-3.6.8-71.el8_10 0.01198 false
CVE-2018-1121 Anchore CVE Low procps-ng-3.3.15-14.el8 0.01165 false
CVE-2022-2183 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.01060 false
CVE-2018-20225 Anchore CVE Low platform-python-pip-9.0.3-24.el8 0.01017 false
CVE-2018-20225 Anchore CVE Low python3-pip-wheel-9.0.3-24.el8 0.01017 false
CVE-2020-10543 Twistlock CVE Medium perl-5.26.3-423.el8_10 0.00734 false
CVE-2025-0938 Twistlock CVE Medium python3-3.6.8-71.el8_10 0.00715 false
CVE-2025-0938 Anchore CVE Medium python3-libs-3.6.8-71.el8_10 0.00715 false
CVE-2025-0938 Anchore CVE Medium platform-python-3.6.8-71.el8_10 0.00715 false
CVE-2022-1720 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00595 false
CVE-2022-2845 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00513 false
CVE-2024-7592 Twistlock CVE Low python3-3.6.8-71.el8_10 0.00468 false
CVE-2024-7592 Anchore CVE Low platform-python-3.6.8-71.el8_10 0.00468 false
CVE-2024-7592 Anchore CVE Low python3-libs-3.6.8-71.el8_10 0.00468 false
CVE-2023-31486 Twistlock CVE Medium perl-HTTP-Tiny-0.074-3.el8 0.00448 false
CVE-2019-9923 Anchore CVE Low tar-2:1.30-11.el8_10 0.00408 false
CVE-2018-19217 Anchore CVE Medium ncurses-6.1-10.20180224.el8 0.00404 false
CVE-2022-1619 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00387 false
CVE-2021-39537 Anchore CVE Low ncurses-6.1-10.20180224.el8 0.00351 false
CVE-2018-20786 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00341 false
CVE-2022-4292 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00322 false
CVE-2018-19211 Anchore CVE Low ncurses-6.1-10.20180224.el8 0.00278 false
CVE-2024-0397 Twistlock CVE Low python3-3.6.8-71.el8_10 0.00226 false
CVE-2024-0397 Anchore CVE Low python3-libs-3.6.8-71.el8_10 0.00226 false
CVE-2024-0397 Anchore CVE Low platform-python-3.6.8-71.el8_10 0.00226 false
CVE-2021-4166 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00224 false
CVE-2024-0727 Anchore CVE Low openssl-1:1.1.1k-14.el8_6 0.00214 false
CVE-2020-12723 Twistlock CVE Medium perl-5.26.3-423.el8_10 0.00201 false
CVE-2021-3974 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00195 false
CVE-2022-3705 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00194 false
CVE-2025-1795 Twistlock CVE Low python3-3.6.8-71.el8_10 0.00184 false
CVE-2025-1795 Anchore CVE Low platform-python-3.6.8-71.el8_10 0.00184 false
CVE-2025-1795 Anchore CVE Low python3-libs-3.6.8-71.el8_10 0.00184 false
CVE-2024-22667 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00179 false
CVE-2022-2285 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00171 false
CVE-2024-41996 Anchore CVE Low openssl-1:1.1.1k-14.el8_6 0.00166 false
CVE-2022-2284 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00164 false
CVE-2021-3927 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00160 false
CVE-2022-2286 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00154 false
CVE-2022-2125 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00153 false
CVE-2020-10878 Twistlock CVE Medium perl-5.26.3-423.el8_10 0.00148 false
CVE-2023-47038 Twistlock CVE Medium perl-5.26.3-423.el8_10 0.00142 false
CVE-2022-4293 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00133 false
CVE-2022-48338 Twistlock CVE Medium emacs-26.1-15.el8_10 0.00119 false
CVE-2024-4741 Anchore CVE Low openssl-1:1.1.1k-14.el8_6 0.00116 false
CVE-2022-2210 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00114 false
CVE-2022-2207 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00114 false
CVE-2025-1215 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00112 false
CVE-2022-2206 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00108 false
CVE-2022-2175 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00108 false
CVE-2022-2129 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00101 false
CVE-2021-20193 Anchore CVE Medium tar-2:1.30-11.el8_10 0.00100 false
CVE-2022-2124 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00098 false
CVE-2022-2126 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00097 false
CVE-2024-45306 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00095 false
CVE-2025-6069 Twistlock CVE Medium python3-3.6.8-71.el8_10 0.00090 false
CVE-2025-6069 Anchore CVE Medium platform-python-3.6.8-71.el8_10 0.00090 false
CVE-2025-6069 Anchore CVE Medium python3-libs-3.6.8-71.el8_10 0.00090 false
CVE-2022-2343 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00090 false
CVE-2023-48706 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00088 false
CVE-2024-13176 Anchore CVE Low openssl-1:1.1.1k-14.el8_6 0.00080 false
CVE-2025-29768 Twistlock CVE Medium vim-8.0.1763-19.el8_6.4 0.00072 false
CVE-2023-5344 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00062 false
CVE-2022-2208 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00062 false
CVE-2025-47907 Anchore CVE High stdlib-go1.23.8 0.00054 false
CVE-2025-47907 Anchore CVE High stdlib-go1.23.8 0.00054 false
CVE-2025-47907 Anchore CVE High stdlib-go1.23.8 0.00054 false
CVE-2025-47907 Anchore CVE High stdlib-go1.23.8 0.00054 false
CVE-2025-47907 Anchore CVE High stdlib-go1.23.8 0.00054 false
CVE-2025-47907 Anchore CVE High stdlib-go1.23.8 0.00054 false
CVE-2025-47907 Anchore CVE High stdlib-go1.23.11 0.00054 false
CVE-2025-47907 Anchore CVE High stdlib-go1.23.8 0.00054 false
CVE-2025-47907 Anchore CVE High stdlib-go1.23.8 0.00054 false
CVE-2022-3256 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00054 false
CVE-2025-45582 Twistlock CVE Medium tar-1.30-11.el8_10 0.00053 false
CVE-2025-45582 Anchore CVE Medium tar-2:1.30-11.el8_10 0.00053 false
CVE-2023-48237 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00053 false
CVE-2023-48233 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00053 false
CVE-2023-48232 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00053 false
CVE-2023-48231 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00052 false
CVE-2022-3296 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00052 false
CVE-2022-3234 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00052 false
CVE-2023-1170 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00051 false
CVE-2024-43802 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00050 false
CVE-2023-50495 Anchore CVE Low ncurses-6.1-10.20180224.el8 0.00050 false
CVE-2022-2287 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00050 false
CVE-2022-3235 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00049 false
CVE-2025-24014 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00047 false
CVE-2023-4751 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00045 false
CVE-2023-48235 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00044 false
CVE-2022-3037 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00044 false
CVE-2023-4738 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00041 false
CVE-2022-2980 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00041 false
CVE-2023-4752 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00040 false
CVE-2023-48236 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00039 false
CVE-2023-48234 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00039 false
CVE-2023-39804 Twistlock CVE Low tar-1.30-11.el8_10 0.00039 false
CVE-2023-39804 Anchore CVE Low tar-2:1.30-11.el8_10 0.00039 false
CVE-2022-2946 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00039 false
CVE-2022-2849 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00038 false
CVE-2023-24056 Anchore CVE Low pkgconf-1.4.2-1.el8 0.00037 false
CVE-2023-24056 Anchore CVE Low pkgconf-pkg-config-1.4.2-1.el8 0.00037 false
CVE-2023-24056 Anchore CVE Low pkgconf-m4-1.4.2-1.el8 0.00037 false
CVE-2023-24056 Anchore CVE Low libpkgconf-1.4.2-1.el8 0.00037 false
CVE-2022-2522 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00037 false
CVE-2023-4750 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00036 false
CVE-2023-4734 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00036 false
CVE-2023-4733 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00036 false
CVE-2022-3153 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00036 false
CVE-2022-2345 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00036 false
CVE-2022-2344 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00036 false
CVE-2025-26603 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00033 false
CVE-2023-1127 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00033 false
CVE-2022-0351 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00033 false
CVE-2022-2819 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00032 false
CVE-2023-4781 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00031 false
CVE-2023-0288 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00030 false
CVE-2023-4735 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00027 false
CVE-2024-43374 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00025 false
CVE-2025-22134 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00023 false
CVE-2023-5535 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00023 false
CVE-2023-1175 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00022 false
CVE-2021-3236 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00022 false
CVE-2025-4516 Twistlock CVE Medium python3-3.6.8-71.el8_10 0.00021 false
CVE-2025-4516 Anchore CVE Medium python3-libs-3.6.8-71.el8_10 0.00021 false
CVE-2025-4516 Anchore CVE Medium platform-python-3.6.8-71.el8_10 0.00021 false
CVE-2022-3352 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00021 false
CVE-2025-4673 Anchore CVE Medium stdlib-go1.23.8 0.00019 false
CVE-2025-4673 Anchore CVE Medium stdlib-go1.23.8 0.00019 false
CVE-2025-4673 Anchore CVE Medium stdlib-go1.23.8 0.00019 false
CVE-2025-4673 Anchore CVE Medium stdlib-go1.23.8 0.00019 false
CVE-2025-4673 Anchore CVE Medium stdlib-go1.23.8 0.00019 false
CVE-2025-4673 Anchore CVE Medium stdlib-go1.23.8 0.00019 false
CVE-2025-4673 Anchore CVE Medium stdlib-go1.23.8 0.00019 false
CVE-2025-4673 Anchore CVE Medium stdlib-go1.23.8 0.00019 false
CVE-2023-5441 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00019 false
CVE-2023-1264 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00019 false
CVE-2022-2923 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00019 false
CVE-2024-41965 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00017 false
CVE-2024-30204 Twistlock CVE Medium emacs-26.1-15.el8_10 0.00017 false
CVE-2023-0049 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00017 false
CVE-2025-53906 Twistlock CVE Medium vim-8.0.1763-19.el8_6.4 0.00016 false
CVE-2025-53905 Twistlock CVE Medium vim-8.0.1763-19.el8_6.4 0.00016 false
CVE-2023-0433 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00016 false
CVE-2023-0054 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00016 false
CVE-2025-50181 Twistlock CVE Medium python-pip-9.0.3-24.el8 0.00015 false
CVE-2025-50181 Anchore CVE Medium platform-python-pip-9.0.3-24.el8 0.00015 false
CVE-2025-50181 Anchore CVE Medium python3-pip-wheel-9.0.3-24.el8 0.00015 false
CVE-2024-47814 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00015 false
CVE-2025-9390 Twistlock CVE Medium vim-8.0.1763-19.el8_6.4 0.00014 false
CVE-2025-9301 Twistlock CVE Low cmake-3.26.5-2.el8 0.00014 false
CVE-2025-9301 Anchore CVE Low cmake-rpm-macros-3.26.5-2.el8 0.00014 false
CVE-2025-9301 Anchore CVE Low cmake-3.26.5-2.el8 0.00014 false
CVE-2025-9301 Anchore CVE Low cmake-data-3.26.5-2.el8 0.00014 false
CVE-2025-9301 Anchore CVE Low cmake-filesystem-3.26.5-2.el8 0.00014 false
CVE-2023-2610 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00014 false
CVE-2025-50182 Twistlock CVE Medium python-pip-9.0.3-24.el8 0.00013 false
CVE-2025-50182 Anchore CVE Medium python3-pip-wheel-9.0.3-24.el8 0.00013 false
CVE-2025-50182 Anchore CVE Medium platform-python-pip-9.0.3-24.el8 0.00013 false
CVE-2023-46246 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00013 false
CVE-2023-0512 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00013 false
CVE-2023-2609 Twistlock CVE Low vim-8.0.1763-19.el8_6.4 0.00012 false
CVE-2025-4674 Anchore CVE High stdlib-go1.23.8 0.00006 false
CVE-2025-4674 Anchore CVE High stdlib-go1.23.8 0.00006 false
CVE-2025-4674 Anchore CVE High stdlib-go1.23.8 0.00006 false
CVE-2025-4674 Anchore CVE High stdlib-go1.23.8 0.00006 false
CVE-2025-4674 Anchore CVE High stdlib-go1.23.8 0.00006 false
CVE-2025-4674 Anchore CVE High stdlib-go1.23.8 0.00006 false
CVE-2025-4674 Anchore CVE High stdlib-go1.23.8 0.00006 false
CVE-2025-4674 Anchore CVE High stdlib-go1.23.8 0.00006 false
e999d81b535588a19a8004807019a2e2 Anchore Compliance Critical N/A N/A
e3832fca2350274d743772f700d1ab2a Anchore Compliance Critical N/A N/A
bf534969579b184968e16f7e26f084ee Anchore Compliance Critical N/A N/A
b19e15e8ad099a83820b7a2d747095fb Anchore Compliance Critical N/A N/A
GHSA-hj4r-2c9c-29h3 Anchore CVE Medium github.com/elastic/beats-v7.6.2+incompatible N/A N/A
749927442314a30176a9113f576bc957 Anchore Compliance Critical N/A N/A
6b00f65b4ea35e4e172d9d09598f54e1 Anchore Compliance Critical N/A N/A
4f7e1bf339d17861105bece4bb0080bf Anchore Compliance Critical N/A N/A
43eefb9293cc0c8d4c8bb4ba620863f5 Anchore Compliance Critical N/A N/A
28a20d9210ade8500a6882a2da439153 Anchore Compliance Critical N/A N/A
1ecec1e40ccbe23f44510a519bf45ad5 Anchore Compliance Critical N/A N/A
06326817a751383683daa4f085406e9e Anchore Compliance Critical N/A N/A

More information can be found in the VAT located here: https://vat.dso.mil/vat/image?imageName=mongodb/mongodb-enterprise/mongodb-agent&tag=108.0.12.8846-1&branch=master

Tasks

Contributor:

  • Provide justifications for findings in the VAT (docs)
  • Apply the StatusVerification label to this issue and wait for feedback

Iron Bank:

  • Review findings and justifications

Note: If the above process is rejected for any reason, the Verification label will be removed and the issue will be sent back to Open. Any comments will be listed in this issue for you to address. Once they have been addressed, you must re-add the Verification label.

Questions?

Contact the Iron Bank team by commenting on this issue with your questions or concerns. If you do not receive a response, add /cc @ironbank-notifications/onboarding.

Additionally, Iron Bank hosts an AMA working session every Wednesday from 1630-1730EST to answer questions.

Edited by CHORE_TOKEN
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information