QID 376399

Date Published: 2022-02-14

QID 376399: MongoDB Multiple Security Vulnerabilities (SERVER-59071,SERVER-36263)

MongoDB is an open-source document database, and NoSQL database.

CVE-2021-32037: User may trigger invariant when allowed to send commands directly to shards.

CVE-2021-20330: Specific replication command with malformed oplog entries can crash secondaries

Affected Versions:
MongoDB Server 5.0.0 versions prior to 5.0.3.
MongoDB Server 4.0.0 versions prior to 4.0.27.
MongoDB Server 4.2.0 versions prior to 4.2.16.
MongoDB Server 4.4.0 versions prior to 4.4.9.

QID Detection Logic:(Authenticated)
This QID checks for vulnerable version of MongoDB installed on the target.

Successful exploitation may allow an authorized user to trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customer are advised to update MongoDb to the latest versions.
    For more information visit SERVER-59071 and SERVER-36263

    CVEs related to QID 376399

    Software Advisories
    Advisory ID Software Component Link
    SERVER-36263 URL Logo jira.mongodb.org/browse/SERVER-36263
    SERVER-59071 URL Logo jira.mongodb.org/browse/SERVER-59071