7.5

CVE-2020-7925

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MongodbMongodb Version >= 4.2.0 < 4.2.9
MongodbMongodb Version4.4.0 Updaterc1
MongodbMongodb Version4.4.0 Updaterc10
MongodbMongodb Version4.4.0 Updaterc11
MongodbMongodb Version4.4.0 Updaterc2
MongodbMongodb Version4.4.0 Updaterc3
MongodbMongodb Version4.4.0 Updaterc4
MongodbMongodb Version4.4.0 Updaterc5
MongodbMongodb Version4.4.0 Updaterc6
MongodbMongodb Version4.4.0 Updaterc7
MongodbMongodb Version4.4.0 Updaterc8
MongodbMongodb Version4.4.0 Updaterc9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.815
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
cna@mongodb.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-475 Undefined Behavior for Input to API

The behavior of this function is undefined unless its control parameter is set to a specific value.