QID 376370
Date Published: 2022-02-14
QID 376370: MongoDB Denial of Service (DoS) Vulnerability (SERVER-51083)
MongoDB is an open-source document database, and NoSQL database.
CVE-2020-7929:A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex.
Affected Versions:
MongoDB Server v3.6 versions prior to 3.6.21.
MongoDB Server v4.0 versions prior to 4.0.20.
QID Detection Logic:(Authenticated)
This QID checks for vulnerable version of MongoDB installed on the target.
Successful exploitation may allow attacker to perform database queries may trigger denial of service by issuing specially crafted queries
Solution
Customer are advised to update MongoDb to the latest versions.
For more information visit MongoDB SERVER-51083
For more information visit MongoDB SERVER-51083
Vendor References
- MongoDB SERVER-51083 -
jira.mongodb.org/browse/SERVER-51083
CVEs related to QID 376370
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SERVER-51083 |
|