Mongodb

Mongodb

77 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 15.12.2021 13:15:07
  • Zuletzt bearbeitet 21.11.2024 05:46:23

An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior t...

  • EPSS 0.47%
  • Veröffentlicht 24.11.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 06:06:45

An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the ...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 23.07.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 05:46:24

Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 ...

  • EPSS 0.29%
  • Veröffentlicht 30.04.2021 09:15:07
  • Zuletzt bearbeitet 21.11.2024 05:46:23

A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.4.

  • EPSS 0.44%
  • Veröffentlicht 01.03.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:03:20

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3....

  • EPSS 0.44%
  • Veröffentlicht 01.03.2021 16:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:01

A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.

  • EPSS 0.48%
  • Veröffentlicht 24.11.2020 11:15:10
  • Zuletzt bearbeitet 21.11.2024 04:39:42

An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB ...

  • EPSS 0.43%
  • Veröffentlicht 23.11.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:02:12

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects MongoDB Server v4.0 versions prior to 4.0.5;...

  • EPSS 0.48%
  • Veröffentlicht 23.11.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:38:01

A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; Mo...

  • EPSS 0.43%
  • Veröffentlicht 23.11.2020 16:15:13
  • Zuletzt bearbeitet 21.11.2024 04:40:47

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to ...