7.5

CVE-2020-7925

Denial of Service when processing malformed Role names

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MongoDB ≫ MongoDB Version >= 4.2.0 < 4.2.9
MongoDB ≫ MongoDB Version 4.4.0 Update rc1
MongoDB ≫ MongoDB Version 4.4.0 Update rc10
MongoDB ≫ MongoDB Version 4.4.0 Update rc11
MongoDB ≫ MongoDB Version 4.4.0 Update rc2
MongoDB ≫ MongoDB Version 4.4.0 Update rc3
MongoDB ≫ MongoDB Version 4.4.0 Update rc4
MongoDB ≫ MongoDB Version 4.4.0 Update rc5
MongoDB ≫ MongoDB Version 4.4.0 Update rc6
MongoDB ≫ MongoDB Version 4.4.0 Update rc7
MongoDB ≫ MongoDB Version 4.4.0 Update rc8
MongoDB ≫ MongoDB Version 4.4.0 Update rc9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.68% 0.75
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
MongoDb 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-475 Undefined Behavior for Input to API

The behavior of this function is undefined unless its control parameter is set to a specific value.

https://jira.mongodb.org/browse/SERVER-49142
Vendor Advisory
Issue Tracking