Mongodb

Mongodb

72 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 14.11.2024 16:15:18
  • Zuletzt bearbeitet 01.10.2025 18:40:03

An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that construct malformed BSON in the MongoDB Server. This issue affects MongoDB Server v5.0 versions prior to 5...

  • EPSS 0.29%
  • Veröffentlicht 21.10.2024 15:15:04
  • Zuletzt bearbeitet 07.11.2024 15:38:32

prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause multiple secondaries crashing leading to no primaries. This issue affects MongoDB Server v6.0 versio...

  • EPSS 0.33%
  • Veröffentlicht 10.09.2024 14:15:13
  • Zuletzt bearbeitet 22.09.2025 18:39:20

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.

  • EPSS 0.06%
  • Veröffentlicht 27.08.2024 12:15:04
  • Zuletzt bearbeitet 16.05.2025 23:15:19

In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cause the MongoDB Server binary to load unintended act...

  • EPSS 0.17%
  • Veröffentlicht 13.08.2024 15:15:18
  • Zuletzt bearbeitet 21.11.2024 09:49:32

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7...

  • EPSS 0.21%
  • Veröffentlicht 07.08.2024 10:15:39
  • Zuletzt bearbeitet 19.09.2024 20:46:04

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of ...

  • EPSS 0.3%
  • Veröffentlicht 01.07.2024 15:15:17
  • Zuletzt bearbeitet 21.11.2024 09:49:31

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels....

  • EPSS 0.61%
  • Veröffentlicht 14.05.2024 16:17:31
  • Zuletzt bearbeitet 29.09.2025 18:05:41

An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and incl...

  • EPSS 0.38%
  • Veröffentlicht 14.05.2024 16:17:31
  • Zuletzt bearbeitet 22.09.2025 13:36:41

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This iss...

  • EPSS 0.25%
  • Veröffentlicht 07.03.2024 17:15:12
  • Zuletzt bearbeitet 11.03.2025 16:56:35

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connect...