QID 376401

Date Published: 2022-02-14

QID 376401: MongoDB Multiple Security Vulnerabilities (SERVER-53929)

MongoDB is an open-source document database, and NoSQL database.

CVE-2021-20326: Specially crafted query may result in a denial of service of mongod.

Affected Versions:
MongoDB Server 4.4.0 versions prior to 4.4.4.

QID Detection Logic:(Authenticated)
This QID checks for vulnerable versions of MongoDB installed on the target.

A user authorized to performing a specific type of find query may trigger a denial of service.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customer are advised to update MongoDb to the latest versions.
    For more information visit SERVER-53929
    Vendor References

    CVEs related to QID 376401

    Software Advisories
    Advisory ID Software Component Link
    SERVER-53929 URL Logo jira.mongodb.org/browse/SERVER-53929