PT-2022-16577 · Mongodb · Mongodb Server+1

Sara Golemon

+1

·

Published

2022-04-21

·

Updated

2024-03-06

·

CVE-2022-24272

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MongoDB Server versions prior to and including v5.0.6
Description An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash.
Recommendations For versions prior to and including v5.0.6, update to a version later than v5.0.6 to resolve the issue. As a temporary workaround, consider restricting access to the $external database to minimize the risk of exploitation.

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-MONGODB-2022-24272
CVE-2022-24272

Affected Products

Mongodb Server
Mongodb