PT-2020-8673 · Mongodb+1 · Mongodb Server+2

Published

2020-11-23

·

Updated

2026-02-25

·

CVE-2018-20802

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: MongoDB Server versions prior to 3.6.9 MongoDB Server versions prior to 4.0.3
Description: A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting QueryPlanner.
Recommendations: For MongoDB Server versions prior to 3.6.9, update to version 3.6.9 or later. For MongoDB Server versions prior to 4.0.3, update to version 4.0.3 or later. As a temporary workaround, consider restricting access to compound indexes in QueryPlanner to minimize the risk of exploitation.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2018-20802
USN-8064-1

Affected Products

Mongodb Server
Mongodb
Ubuntu