The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the regex match can start in the middle of a multi-code-unit character, triggering an assertion during query execution.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Mongodb Mongodb
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
|
7.0.0
|
7.0.41
|
|
Mongodb Mongodb
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
|
8.0.0
|
8.0.30
|
|
Mongodb Mongodb
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
|
8.3.0
|
8.3.9
|