{"id":"CLSA-2022-1668117586","summary":"Fix CVE(s): CVE-2019-2386","details":"\n   * SECURITY UPDATE: After user deletion in MongoDB Server the improper\n     invalidation of authorization sessions allows an authenticated user's\n     session to persist and become conflated with new accounts, if those\n     accounts reuse the names of deleted ones\n     - debian/patches/CVE-2019-2386.patch: Validate unique User ID on\n     UserCache hit\n     - CVE-2019-2386","modified":"2026-06-04T09:45:52.735552675Z","published":"2022-11-10T21:59:46Z","upstream":["CVE-2019-2386"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16-els/CLSA-2022-1668117586"}],"affected":[{"package":{"name":"mongodb","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/mongodb?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.6.10-0ubuntu1+tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1668117586.json"}},{"package":{"name":"mongodb-clients","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/mongodb-clients?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.6.10-0ubuntu1+tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1668117586.json"}},{"package":{"name":"mongodb-server","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/mongodb-server?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.6.10-0ubuntu1+tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2022-1668117586.json"}}],"schema_version":"1.7.5"}