PT-2022-16577 · Mongodb · Mongodb Server+1
Sara Golemon
+1
·
Published
2022-04-21
·
Updated
2024-03-06
·
CVE-2022-24272
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MongoDB Server versions prior to and including v5.0.6
Description
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the
$external database. This may result in mongod denial of service or server crash.Recommendations
For versions prior to and including v5.0.6, update to a version later than v5.0.6 to resolve the issue. As a temporary workaround, consider restricting access to the
$external database to minimize the risk of exploitation.Fix
DoS
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mongodb Server
Mongodb