An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 4
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Mongodb Mongodb
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
|
7.0.0
|
7.0.35
|
|
Mongodb Mongodb
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
|
8.0.0
|
8.0.24
|
|
Mongodb Mongodb
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
|
8.2.0
|
8.2.10
|
|
Mongodb Mongodb
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
|
8.3.0
|
8.3.3
|