An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HMongodb
APPMongodb3.4.0 – 3.4.24 (excl.)3.6.0 – 3.6.15 (excl.)4.0.0 – 4.0.13 (excl.)4.2.0 – 4.2.1 (excl.)
Related vulnerabilities
Heap Buffer Overflow w MongoDB (tryb compute) podczas przetwarzania BSON
MongoDB: podatność w kompresji protokołu sieciowego — DoS i modyfikacja pamięci
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by ...
MongoDB: DoS poprzez wyrażenie agregacji $_internalIndexKey z compound wildcard index
MongoDB – wyczerpanie pamięci przez wyrażenia generujące duże tablice (DoS)