QID 379091

Date Published: 2023-12-11

QID 379091: MongoDB Denial of Service (DoS) Vulnerability (SERVER-63968)

MongoDB is an open-source document database, and NoSQL database.

CVE-2022-24272: An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the external database.

Affected Versions:
MongoDB Server v5.0 versions, prior to and including v5.0.6

QID Detection Logic:(Authenticated)
This QID checks for vulnerable versions of MongoDB installed on the target.

An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the external database.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customer are advised to update MongoDb to the latest versions.
    For more information visit SERVER-63968
    Vendor References

    CVEs related to QID 379091

    Software Advisories
    Advisory ID Software Component Link
    SERVER-63968 URL Logo jira.mongodb.org/browse/SERVER-63968