QID 376400
Date Published: 2022-02-14
QID 376400: MongoDB Multiple Security Vulnerabilities (SERVER-38275)
MongoDB is an open-source document database, and NoSQL database.
CVE-2018-25004:Invariant failure when explaining a find with a UUID.
Affected Versions:
MongoDB Server 4.0.0 versions prior to 4.0.6.
MongoDB Server 3.6.0 versions prior to 3.6.11.
QID Detection Logic:(Authenticated)
This QID checks for vulnerable version of MongoDB installed on the target.
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query
Solution
Customer are advised to update MongoDb to the latest versions.
For more information visit SERVER-38275
For more information visit SERVER-38275
Vendor References
- SERVER-38275 -
jira.mongodb.org/browse/SERVER-38275
CVEs related to QID 376400
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SERVER-38275 |
|