Bump Windows package dependencies

XMLWordPrintableJSON

    • Fully Compatible
    • ALL
    • v4.2, v4.0, v3.6, v3.4
    • Security 2019-07-15, Security 2019-07-29
    • None
    • 0
    • None
    • None
    • None
    • None
    • None
    • None

      CVE-2019-2390

      Description
      An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server versions less than 4.0.11, 3.6.14, and 3.4.22 to run attacker defined code as the user running the utility.

      Credit
      Rich Mirch

            Assignee:
            Spencer Jackson
            Reporter:
            Spencer Jackson
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: