https://www.talosintelligence.com/vulnerability_reports/TALO…
8/6/19
An exploitable authentication vulnerability exists in MongoDB Server prior to version 4.0.9. Access to a MongoDB database server can be persisted after user deletion by reusing an established session of said user.
Tested Versions
MongoDB Server 4.0.5 MongoDB Server 3.4.18