CVE-2023-1409
- EPSS 0.47%
- Veröffentlicht 23.08.2023 16:15:08
- Zuletzt bearbeitet 13.02.2025 17:15:58
If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that client certificate validation may not...
CVE-2022-24272
- EPSS 0.46%
- Veröffentlicht 21.04.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:04
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 ...
CVE-2021-32040
- EPSS 0.83%
- Veröffentlicht 12.04.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:45
It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur...
CVE-2021-32036
- EPSS 0.14%
- Veröffentlicht 04.02.2022 23:15:11
- Zuletzt bearbeitet 21.11.2024 06:06:45
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare c...
CVE-2021-32039
- EPSS 0.14%
- Veröffentlicht 20.01.2022 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:45
Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability af...
CVE-2021-20330
- EPSS 0.38%
- Veröffentlicht 15.12.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:23
An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior t...
CVE-2021-32037
- EPSS 0.47%
- Veröffentlicht 24.11.2021 16:15:13
- Zuletzt bearbeitet 21.11.2024 06:06:45
An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the ...
CVE-2021-20333
- EPSS 0.44%
- Veröffentlicht 23.07.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:24
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 ...
CVE-2021-20326
- EPSS 0.29%
- Veröffentlicht 30.04.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:46:23
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.4.
CVE-2018-25004
- EPSS 0.44%
- Veröffentlicht 01.03.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:03:20
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3....