Mongodb

Mongodb

69 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Published 27.08.2024 12:15:04
  • Last modified 16.05.2025 23:15:19

In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cause the MongoDB Server binary to load unintended act...

  • EPSS 0.17%
  • Published 13.08.2024 15:15:18
  • Last modified 21.11.2024 09:49:32

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7...

  • EPSS 0.14%
  • Published 07.08.2024 10:15:39
  • Last modified 19.09.2024 20:46:04

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of ...

  • EPSS 0.28%
  • Published 01.07.2024 15:15:17
  • Last modified 21.11.2024 09:49:31

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels....

  • EPSS 0.41%
  • Published 14.05.2024 16:17:31
  • Last modified 22.09.2025 13:36:41

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This iss...

  • EPSS 0.61%
  • Published 14.05.2024 16:17:31
  • Last modified 29.09.2025 18:05:41

An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and incl...

  • EPSS 0.2%
  • Published 07.03.2024 17:15:12
  • Last modified 11.03.2025 16:56:35

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connect...

  • EPSS 0.25%
  • Published 23.08.2023 16:15:08
  • Last modified 13.02.2025 17:15:58

If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that client certificate validation may not...

  • EPSS 0.46%
  • Published 21.04.2022 11:15:08
  • Last modified 21.11.2024 06:50:04

An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 ...

  • EPSS 0.83%
  • Published 12.04.2022 15:15:07
  • Last modified 21.11.2024 06:06:45

It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur...