Search

Find a vulnerability

Search criteria

    10 vulnerabilities found for MongoDB by MongoDB

    CERTFR-2026-AVI-1234

    Vulnerability from certfr_avis - Published: 2026-09-28 - Updated: 2026-09-28

    De multiples vulnรฉrabilitรฉs ont รฉtรฉ dรฉcouvertes dans MongoDB. Elles permettent ร  un attaquant de provoquer une atteinte ร  l'intรฉgritรฉ des donnรฉes, un contournement de la politique de sรฉcuritรฉ et un problรจme de sรฉcuritรฉ non spรฉcifiรฉ par l'รฉditeur.

    Solutions

    Se rรฉfรฉrer au bulletin de sรฉcuritรฉ de l'รฉditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    MongoDB C Driver mongo-c-driver versions antรฉrieures ร  2.5.5
    MongoDB Compass Compass versions antรฉrieures ร  1.49.12
    MongoDB MongoDB MongoDB versions antรฉrieures ร  1.21.10
    MongoDB C Driver mongo-c-driver versions antรฉrieures ร  1.30.12
    MongoDB MongoDB-extension MongoDB-extension versions 2.2.x ร  2.5.x antรฉrieures ร  2.5.3
    MongoDB PyMongo pymongo versions antรฉrieures ร  4.18.2
    MongoDB MongoDB MongoDB versions 2.2.x ร  2.5.x antรฉrieures ร  2.5.3
    MongoDB MongoDB MongoDB versions 2.x antรฉrieures ร  2.1.10
    MongoDB MongoDB-extension MongoDB-extension versions 2.x antรฉrieures ร  2.1.10
    MongoDB MongoDB-extension MongoDB-extension versions antรฉrieures ร  1.21.10

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "mongo-c-driver versions ant\u00e9rieures \u00e0 2.5.5",
          "product": {
            "name": "C Driver",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        },
        {
          "description": "Compass versions ant\u00e9rieures \u00e0 1.49.12",
          "product": {
            "name": "Compass",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        },
        {
          "description": "MongoDB versions ant\u00e9rieures \u00e0 1.21.10",
          "product": {
            "name": "MongoDB",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        },
        {
          "description": "mongo-c-driver versions ant\u00e9rieures \u00e0 1.30.12",
          "product": {
            "name": "C Driver",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        },
        {
          "description": "MongoDB-extension versions 2.2.x \u00e0 2.5.x ant\u00e9rieures \u00e0 2.5.3",
          "product": {
            "name": "MongoDB-extension",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        },
        {
          "description": "pymongo versions ant\u00e9rieures \u00e0 4.18.2",
          "product": {
            "name": "PyMongo",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        },
        {
          "description": "MongoDB versions 2.2.x \u00e0 2.5.x ant\u00e9rieures \u00e0 2.5.3",
          "product": {
            "name": "MongoDB",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        },
        {
          "description": "MongoDB versions 2.x ant\u00e9rieures \u00e0 2.1.10",
          "product": {
            "name": "MongoDB",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        },
        {
          "description": "MongoDB-extension versions 2.x ant\u00e9rieures \u00e0 2.1.10",
          "product": {
            "name": "MongoDB-extension",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        },
        {
          "description": "MongoDB-extension versions ant\u00e9rieures \u00e0 1.21.10",
          "product": {
            "name": "MongoDB-extension",
            "vendor": {
              "name": "MongoDB",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-96745",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96745"
        },
        {
          "name": "CVE-2026-96748",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96748"
        },
        {
          "name": "CVE-2026-96747",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96747"
        },
        {
          "name": "CVE-2026-96749",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96749"
        },
        {
          "name": "CVE-2026-96746",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-96746"
        }
      ],
      "initial_release_date": "2026-09-28T00:00:00",
      "last_revision_date": "2026-09-28T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1234",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-28T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans MongoDB. Elles permettent \u00e0 un attaquant de provoquer une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es, un contournement de la politique de s\u00e9curit\u00e9 et un probl\u00e8me de s\u00e9curit\u00e9 non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans MongoDB",
      "vendor_advisories": [
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 MongoDB GHSA-frjf-h5jg-4v46",
          "url": "https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-frjf-h5jg-4v46"
        },
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 MongoDB GHSA-qx36-8mw2-4r3x",
          "url": "https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-qx36-8mw2-4r3x"
        },
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 MongoDB GHSA-vp6j-j7w5-5xjj",
          "url": "https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-vp6j-j7w5-5xjj"
        },
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 MongoDB 3579",
          "url": "https://github.com/mongodb/laravel-mongodb/pull/3579"
        },
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 MongoDB v1.49.12",
          "url": "https://github.com/mongodb-js/compass/releases/tag/v1.49.12"
        },
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 MongoDB GHSA-cmvj-vxvq-rh2c",
          "url": "https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-cmvj-vxvq-rh2c"
        },
        {
          "published_at": "2026-09-24",
          "title": "Bulletin de s\u00e9curit\u00e9 MongoDB GHSA-v4x9-3549-crwv",
          "url": "https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-v4x9-3549-crwv"
        }
      ]
    }

    CVE-2026-11933 (GCVE-0-2026-11933)

    Vulnerability from cvelistv5 โ€“ Published: 2026-06-12 01:57 โ€“ Updated: 2026-06-13 03:55
    VLAI
    Title
    Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion
    Summary
    A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-06-12 00:00 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    MongoDB MongoDB Affected: 8.3.0 , โ‰ค 8.3.3 (semver)
    Affected: 8.2.0 , โ‰ค 8.2.10 (semver)
    Affected: 8.0.0 , โ‰ค 8.0.25 (semver)
    Affected: 7.0.0 , โ‰ค 7.0.36 (semver)
    Affected: 6.0 , โ‰ค 6.0.28 (semver)
    Affected: 5.0 , โ‰ค 5.0.33 (semver)
    Affected: 4.4.0 , โ‰ค 4.4.30 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-11933",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-12T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-13T03:55:46.393Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "MongoDB",
              "vendor": "MongoDB",
              "versions": [
                {
                  "lessThanOrEqual": "8.3.3",
                  "status": "affected",
                  "version": "8.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.2.10",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "8.0.25",
                  "status": "affected",
                  "version": "8.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "7.0.36",
                  "status": "affected",
                  "version": "7.0.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.0.28",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.0.33",
                  "status": "affected",
                  "version": "5.0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "4.4.30",
                  "status": "affected",
                  "version": "4.4.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A use-after-free vulnerability exists in MongoDB Server\u0027s server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash."
                }
              ],
              "value": "A use-after-free vulnerability exists in MongoDB Server\u0027s server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787: Out-of-bounds Write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-12T01:58:46.264Z",
            "orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
            "shortName": "mongodb"
          },
          "references": [
            {
              "url": "https://jira.mongodb.org/browse/SERVER-128125"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
        "assignerShortName": "mongodb",
        "cveId": "CVE-2026-11933",
        "datePublished": "2026-06-12T01:57:32.014Z",
        "dateReserved": "2026-06-10T18:54:51.125Z",
        "dateUpdated": "2026-06-13T03:55:46.393Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-9754 (GCVE-0-2026-9754)

    Vulnerability from cvelistv5 โ€“ Published: 2026-06-09 22:33 โ€“ Updated: 2026-06-10 18:29
    VLAI
    Title
    Stack memory disclosure in filemd5 command
    Summary
    An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2026-06-10 18:29 UTC
    CWE
    • CWE-457 - Use of uninitialized variable
    References
    Impacted products
    Vendor Product Version
    MongoDB MongoDB Affected: 8.3.0 , < 8.3.3 (semver)
    Affected: 8.2.0 , < 8.2.10 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-9754",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-10T18:29:32.795310Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-10T18:29:51.926Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "MongoDB",
              "vendor": "MongoDB",
              "versions": [
                {
                  "lessThan": "8.3.3",
                  "status": "affected",
                  "version": "8.3.0",
                  "versionType": "semver"
                },
                {
                  "lessThan": "8.2.10",
                  "status": "affected",
                  "version": "8.2.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command"
                }
              ],
              "value": "An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command"
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-457",
                  "description": "CWE-457 Use of uninitialized variable",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-09T22:33:21.203Z",
            "orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
            "shortName": "mongodb"
          },
          "references": [
            {
              "url": "https://jira.mongodb.org/browse/SERVER-122207"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Stack memory disclosure in filemd5 command",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
        "assignerShortName": "mongodb",
        "cveId": "CVE-2026-9754",
        "datePublished": "2026-06-09T22:33:21.203Z",
        "dateReserved": "2026-05-27T17:49:33.907Z",
        "dateUpdated": "2026-06-10T18:29:51.926Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-1351 (GCVE-0-2024-1351)

    Vulnerability from cvelistv5 โ€“ Published: 2024-03-07 16:10 โ€“ Updated: 2025-02-13 17:27
    VLAI
    Title
    MongoDB Server may allow successful untrusted connection
    Summary
    Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28. Required Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-03-07 18:56 UTC
    CWE
    • CWE-295 - Improper Certificate Validation
    Impacted products
    Vendor Product Version
    MongoDB Inc MongoDB Server Affected: 7.0 , โ‰ค 7.0.5 (custom)
    Affected: 6.0 , โ‰ค 6.0.13 (custom)
    Affected: 5.0 , โ‰ค 5.0.24 (custom)
    Affected: 4.4 , โ‰ค 4.4.28 (custom)
    Create a notification for this product.
    mongodb mongodb Affected: 7.0 , โ‰ค 7.0.5 (custom)
    Affected: 6.0 , โ‰ค 6.0.13 (custom)
    Affected: 5.0 , โ‰ค 5.0.24 (custom)
    Affected: 4.4 , โ‰ค 4.4.28 (custom)
        cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-02-29 09:31
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T18:33:25.588Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jira.mongodb.org/browse/SERVER-72839"
              },
              {
                "tags": [
                  "release-notes",
                  "x_transferred"
                ],
                "url": "https://www.mongodb.com/docs/v5.0/release-notes/5.0/#5.0.25---february-28--2024"
              },
              {
                "tags": [
                  "release-notes",
                  "x_transferred"
                ],
                "url": "https://www.mongodb.com/docs/v6.0/release-notes/6.0/#6.0.14---feb-28--2024"
              },
              {
                "tags": [
                  "release-notes",
                  "x_transferred"
                ],
                "url": "https://www.mongodb.com/docs/manual/release-notes/7.0/#7.0.6---feb-28--2024"
              },
              {
                "tags": [
                  "release-notes",
                  "x_transferred"
                ],
                "url": "https://www.mongodb.com/docs/manual/release-notes/4.4/#4.4.29---february-28--2024"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20240524-0010/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mongodb",
                "vendor": "mongodb",
                "versions": [
                  {
                    "lessThanOrEqual": "7.0.5",
                    "status": "affected",
                    "version": "7.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "6.0.13",
                    "status": "affected",
                    "version": "6.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "5.0.24",
                    "status": "affected",
                    "version": "5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "4.4.28",
                    "status": "affected",
                    "version": "4.4",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-1351",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-07T18:56:20.004972Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-15T17:06:22.918Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "MongoDB Server",
              "vendor": "MongoDB Inc",
              "versions": [
                {
                  "lessThanOrEqual": "7.0.5",
                  "status": "affected",
                  "version": "7.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "6.0.13",
                  "status": "affected",
                  "version": "6.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "5.0.24",
                  "status": "affected",
                  "version": "5.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "4.4.28",
                  "status": "affected",
                  "version": "4.4",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "configurations": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.\u003cbr\u003e"
                }
              ],
              "value": "A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured."
            }
          ],
          "datePublic": "2024-02-29T09:31:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eUnder certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections  that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28.\u003c/p\u003e\u003cp\u003eRequired Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.\u003c/p\u003e"
                }
              ],
              "value": "Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections  that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28.\n\nRequired Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295: Improper Certificate Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-10T16:11:00.782Z",
            "orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
            "shortName": "mongodb"
          },
          "references": [
            {
              "url": "https://jira.mongodb.org/browse/SERVER-72839"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://www.mongodb.com/docs/v5.0/release-notes/5.0/#5.0.25---february-28--2024"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://www.mongodb.com/docs/v6.0/release-notes/6.0/#6.0.14---feb-28--2024"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://www.mongodb.com/docs/manual/release-notes/7.0/#7.0.6---feb-28--2024"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://www.mongodb.com/docs/manual/release-notes/4.4/#4.4.29---february-28--2024"
            },
            {
              "url": "https://security.netapp.com/advisory/ntap-20240524-0010/"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "MongoDB Server may allow successful untrusted connection",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
        "assignerShortName": "mongodb",
        "cveId": "CVE-2024-1351",
        "datePublished": "2024-03-07T16:10:19.597Z",
        "dateReserved": "2024-02-08T16:36:39.507Z",
        "dateUpdated": "2025-02-13T17:27:37.200Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-32040 (GCVE-0-2021-32040)

    Vulnerability from cvelistv5 โ€“ Published: 2022-04-12 14:15 โ€“ Updated: 2024-09-16 20:03
    VLAI
    Title
    Large aggregation pipelines with a specific stage can crash mongod under default configuration
    Summary
    It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB Server v4.4 versions prior to and including 4.4.28, MongoDB Server v5.0 versions prior to 5.0.4 and MongoDB Server v4.2 versions prior to 4.2.16. Workaround:ย >= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-02-23 18:16 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    MongoDB Inc. MongoDB Server Affected: 5.0 , < 5.0.4 (custom)
    Affected: 4.4 , โ‰ค 4.4.28 (custom)
    Affected: 4.2 , < 4.2.16 (custom)
    Create a notification for this product.
    mongodb mongodb Affected: 5.0 , < 5.0.4 (custom)
    Affected: 4.4 , โ‰ค 4.4.28 (custom)
    Affected: 4.2 , < 4.2.16 (custom)
        cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2022-04-11 23:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T23:17:29.135Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.mongodb.org/browse/SERVER-58203"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.mongodb.org/browse/SERVER-59299"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.mongodb.org/browse/SERVER-60218"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20220609-0005/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mongodb",
                "vendor": "mongodb",
                "versions": [
                  {
                    "lessThan": "5.0.4",
                    "status": "affected",
                    "version": "5.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "4.4.28",
                    "status": "affected",
                    "version": "4.4",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.2.16",
                    "status": "affected",
                    "version": "4.2",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2021-32040",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-02-23T18:16:37.734248Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-15T17:07:34.494Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "MongoDB Server",
              "vendor": "MongoDB Inc.",
              "versions": [
                {
                  "lessThan": "5.0.4",
                  "status": "affected",
                  "version": "5.0",
                  "versionType": "custom"
                },
                {
                  "lessThanOrEqual": "4.4.28",
                  "status": "affected",
                  "version": "4.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.2.16",
                  "status": "affected",
                  "version": "4.2",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-04-11T23:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eIt may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects \u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eMongoDB Server v4.4 versions prior to and including 4.4.28, MongoDB Server v5.0 versions prior to 5.0.4 and MongoDB Server v4.2 versions prior to 4.2.16.\u003c/span\u003e\u003c/p\u003e\u003cp\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eWorkaround:\u0026nbsp;\u0026gt;= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB Server v4.4 versions prior to and including 4.4.28, MongoDB Server v5.0 versions prior to 5.0.4 and MongoDB Server v4.2 versions prior to 4.2.16.\n\nWorkaround:\u00a0\u003e= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121 Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-02-23T16:04:43.143Z",
            "orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
            "shortName": "mongodb"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.mongodb.org/browse/SERVER-58203"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.mongodb.org/browse/SERVER-59299"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.mongodb.org/browse/SERVER-60218"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://security.netapp.com/advisory/ntap-20220609-0005/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Large aggregation pipelines with a specific stage can crash mongod under default configuration",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u0026gt;= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash."
                }
              ],
              "value": "\u003e= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cna@mongodb.com",
              "DATE_PUBLIC": "2022-04-12T20:00:00.000Z",
              "ID": "CVE-2021-32040",
              "STATE": "PUBLIC",
              "TITLE": "Large aggregation pipelines with a specific stage can crash mongod under default configuration"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MongoDB Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "5.0",
                                "version_value": "5.0.4"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "4.4",
                                "version_value": "4.4.11"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "4.2",
                                "version_value": "4.2.16"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "MongoDB Inc."
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB versions prior to 5.0.4, 4.4.11, 4.2.16."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-121 Stack-based Buffer Overflow"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.mongodb.org/browse/SERVER-58203",
                  "refsource": "MISC",
                  "url": "https://jira.mongodb.org/browse/SERVER-58203"
                },
                {
                  "name": "https://jira.mongodb.org/browse/SERVER-59299",
                  "refsource": "MISC",
                  "url": "https://jira.mongodb.org/browse/SERVER-59299"
                },
                {
                  "name": "https://jira.mongodb.org/browse/SERVER-60218",
                  "refsource": "MISC",
                  "url": "https://jira.mongodb.org/browse/SERVER-60218"
                },
                {
                  "name": "https://security.netapp.com/advisory/ntap-20220609-0005/",
                  "refsource": "CONFIRM",
                  "url": "https://security.netapp.com/advisory/ntap-20220609-0005/"
                }
              ]
            },
            "source": {
              "discovery": "EXTERNAL"
            },
            "work_around": [
              {
                "lang": "en",
                "value": "\u003e=4.2.16 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash."
              }
            ]
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
        "assignerShortName": "mongodb",
        "cveId": "CVE-2021-32040",
        "datePublished": "2022-04-12T14:15:16.692Z",
        "dateReserved": "2021-05-05T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:03:21.667Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-32039 (GCVE-0-2021-32039)

    Vulnerability from cvelistv5 โ€“ Published: 2022-01-20 14:50 โ€“ Updated: 2024-09-17 01:51
    VLAI
    Title
    MongoDB Extension for VS Code may unexpectedly store credentials locally in clear text
    Summary
    Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-04-22 18:21 UTC
    CWE
    • CWE-522 - Insufficiently Protected Credentials
    References
    Impacted products
    Vendor Product Version
    MongoDB Inc. MongoDB for VS Code Affected: MongoDB for VS Code , โ‰ค 0.7.0 (custom)
    Create a notification for this product.
    mongodb mongodb Affected: -
        cpe:2.3:a:mongodb:mongodb:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2022-01-20 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:mongodb:mongodb:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mongodb",
                "vendor": "mongodb",
                "versions": [
                  {
                    "status": "affected",
                    "version": "-"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2021-32039",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-22T18:21:40.886484Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:13:21.338Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T23:17:28.896Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://github.com/mongodb-js/vscode/releases/tag/v0.8.0"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.mongodb.org/browse/VSCODE-313"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "MongoDB for VS Code",
              "vendor": "MongoDB Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "0.7.0",
                  "status": "affected",
                  "version": "MongoDB for VS Code",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-01-20T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eUsers with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0\u003c/p\u003e"
                }
              ],
              "value": "Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-522",
                  "description": "CWE-522: Insufficiently Protected Credentials",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-23T16:28:19.416Z",
            "orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
            "shortName": "mongodb"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/mongodb-js/vscode/releases/tag/v0.8.0"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.mongodb.org/browse/VSCODE-313"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "MongoDB Extension for VS Code may unexpectedly store credentials locally in clear text",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cna@mongodb.com",
              "DATE_PUBLIC": "2022-01-20T18:13:00.000Z",
              "ID": "CVE-2021-32039",
              "STATE": "PUBLIC",
              "TITLE": "MongoDB Extension for VS Code may unexpectedly store credentials locally in clear text"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MongoDB for VS Code",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c=",
                                "version_name": "MongoDB for VS Code",
                                "version_value": "0.7.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "MongoDB Inc."
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0"
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-522: Insufficiently Protected Credentials"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://github.com/mongodb-js/vscode/releases/tag/v0.8.0",
                  "refsource": "MISC",
                  "url": "https://github.com/mongodb-js/vscode/releases/tag/v0.8.0"
                },
                {
                  "name": "https://jira.mongodb.org/browse/VSCODE-313",
                  "refsource": "MISC",
                  "url": "https://jira.mongodb.org/browse/VSCODE-313"
                }
              ]
            },
            "source": {
              "discovery": "INTERNAL"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
        "assignerShortName": "mongodb",
        "cveId": "CVE-2021-32039",
        "datePublished": "2022-01-20T14:50:10.319Z",
        "dateReserved": "2021-05-05T00:00:00.000Z",
        "dateUpdated": "2024-09-17T01:51:09.452Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-20330 (GCVE-0-2021-20330)

    Vulnerability from cvelistv5 โ€“ Published: 2021-12-15 12:30 โ€“ Updated: 2024-09-16 17:23
    VLAI
    Title
    Specific replication command with malformed oplog entries can crash secondaries
    Summary
    An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-01-23 21:25 UTC
    CWE
    • CWE-20 - Improper Input Validation
    References
    Impacted products
    Vendor Product Version
    MongoDB Inc. MongoDB Server Affected: 4.0 , < 4.0.27 (custom)
    Affected: 4.2 , < 4.2.16 (custom)
    Affected: 4.4 , < 4.4.9 (custom)
    Create a notification for this product.
    mongodb mongodb Affected: 4.0 , < 4.0.27 (custom)
    Affected: 4.2 , < 4.2.18 (custom)
    Affected: 4.4 , < 4.4.9 (custom)
        cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2021-12-15 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T17:37:23.911Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.mongodb.org/browse/SERVER-36263"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mongodb",
                "vendor": "mongodb",
                "versions": [
                  {
                    "lessThan": "4.0.27",
                    "status": "affected",
                    "version": "4.0",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.2.18",
                    "status": "affected",
                    "version": "4.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.4.9",
                    "status": "affected",
                    "version": "4.4",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2021-20330",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-23T21:25:43.265292Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-15T17:08:47.259Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "MongoDB Server",
              "vendor": "MongoDB Inc.",
              "versions": [
                {
                  "lessThan": "4.0.27",
                  "status": "affected",
                  "version": "4.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.2.16",
                  "status": "affected",
                  "version": "4.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.4.9",
                  "status": "affected",
                  "version": "4.4",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2021-12-15T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.\u003c/p\u003e"
                }
              ],
              "value": "An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-23T16:07:57.784Z",
            "orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
            "shortName": "mongodb"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.mongodb.org/browse/SERVER-36263"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Specific replication command with malformed oplog entries can crash secondaries",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cna@mongodb.com",
              "DATE_PUBLIC": "2021-12-15T16:00:00.000Z",
              "ID": "CVE-2021-20330",
              "STATE": "PUBLIC",
              "TITLE": "Specific replication command with malformed oplog entries can crash secondaries"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MongoDB Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "4.0",
                                "version_value": "4.0.27"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "4.2",
                                "version_value": "4.2.16"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "4.4",
                                "version_value": "4.4.9"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "MongoDB Inc."
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.25; MongoDB Server v4.2 versions prior to 4.2.14; MongoDB Server v4.4 versions prior to 4.4.6."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-20 Improper Input Validation"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.mongodb.org/browse/SERVER-36263",
                  "refsource": "MISC",
                  "url": "https://jira.mongodb.org/browse/SERVER-36263"
                }
              ]
            },
            "source": {
              "discovery": "INTERNAL"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
        "assignerShortName": "mongodb",
        "cveId": "CVE-2021-20330",
        "datePublished": "2021-12-15T12:30:10.405Z",
        "dateReserved": "2020-12-17T00:00:00.000Z",
        "dateUpdated": "2024-09-16T17:23:58.888Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-32037 (GCVE-0-2021-32037)

    Vulnerability from cvelistv5 โ€“ Published: 2021-11-24 10:40 โ€“ Updated: 2024-09-16 22:26
    VLAI
    Title
    User may trigger invariant when allowed to send commands directly to shards
    Summary
    An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the address of the shards and to log in to the shards of an auth enabled environment. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.2.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-01-24 16:19 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    MongoDB Inc. MongoDB Server Affected: 5.0 , โ‰ค 5.0.2 (custom)
    Create a notification for this product.
    mongodb mongodb Affected: 5.0 , โ‰ค 5.0.2 (custom)
        cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2021-11-24 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T23:17:28.828Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.mongodb.org/browse/SERVER-59071"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mongodb",
                "vendor": "mongodb",
                "versions": [
                  {
                    "lessThanOrEqual": "5.0.2",
                    "status": "affected",
                    "version": "5.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2021-32037",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-24T16:19:37.309389Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-15T17:09:26.403Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "MongoDB Server",
              "vendor": "MongoDB Inc.",
              "versions": [
                {
                  "lessThanOrEqual": "5.0.2",
                  "status": "affected",
                  "version": "5.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2021-11-24T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eAn authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the address of the shards and to log in to the shards of an auth enabled environment. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.2.\u003c/p\u003e"
                }
              ],
              "value": "An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the address of the shards and to log in to the shards of an auth enabled environment. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.2."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-617",
                  "description": "CWE-617 Reachable Assertion",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-23T16:23:54.539Z",
            "orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
            "shortName": "mongodb"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.mongodb.org/browse/SERVER-59071"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "User may trigger invariant when allowed to send commands directly to shards",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cna@mongodb.com",
              "DATE_PUBLIC": "2021-11-24T14:09:00.000Z",
              "ID": "CVE-2021-32037",
              "STATE": "PUBLIC",
              "TITLE": "User may trigger invariant when allowed to send commands directly to shards"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MongoDB Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c=",
                                "version_name": "5.0",
                                "version_value": "5.0.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "MongoDB Inc."
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the address of the shards and to log in to the shards of an auth enabled environment."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-617 Reachable Assertion"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.mongodb.org/browse/SERVER-59071",
                  "refsource": "MISC",
                  "url": "https://jira.mongodb.org/browse/SERVER-59071"
                }
              ]
            },
            "source": {
              "discovery": "EXTERNAL"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
        "assignerShortName": "mongodb",
        "cveId": "CVE-2021-32037",
        "datePublished": "2021-11-24T10:40:10.557Z",
        "dateReserved": "2021-05-05T00:00:00.000Z",
        "dateUpdated": "2024-09-16T22:26:43.627Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-7929 (GCVE-0-2020-7929)

    Vulnerability from cvelistv5 โ€“ Published: 2021-03-01 16:05 โ€“ Updated: 2024-09-16 19:46
    VLAI
    Title
    Specially crafted regex query can cause DoS
    Summary
    A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-01-23 18:12 UTC
    CWE
    • CWE-185 - Incorrect Regular Expression
    References
    Impacted products
    Vendor Product Version
    MongoDB Inc. MongoDB Server Affected: 3.6 , < 3.6.21 (custom)
    Affected: 4.0 , < 4.0.20 (custom)
    Create a notification for this product.
    mongodb mongodb Affected: 3.6 , < 3.6.21 (custom)
    Affected: 4.0 , < 4.0.20 (custom)
        cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2021-02-26 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T09:48:24.522Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.mongodb.org/browse/SERVER-51083"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mongodb",
                "vendor": "mongodb",
                "versions": [
                  {
                    "lessThan": "3.6.21",
                    "status": "affected",
                    "version": "3.6",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.20",
                    "status": "affected",
                    "version": "4.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-7929",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-01-23T18:12:01.677275Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-15T17:22:54.094Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "MongoDB Server",
              "vendor": "MongoDB Inc.",
              "versions": [
                {
                  "lessThan": "3.6.21",
                  "status": "affected",
                  "version": "3.6",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.0.20",
                  "status": "affected",
                  "version": "4.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2021-02-26T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.\u003c/p\u003e"
                }
              ],
              "value": "A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-185",
                  "description": "CWE-185 Incorrect Regular Expression",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-23T15:49:00.951Z",
            "orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
            "shortName": "mongodb"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.mongodb.org/browse/SERVER-51083"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Specially crafted regex query can cause DoS",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cna@mongodb.com",
              "DATE_PUBLIC": "2021-02-26T17:00:00.000Z",
              "ID": "CVE-2020-7929",
              "STATE": "PUBLIC",
              "TITLE": "Specially crafted regex query can cause DoS"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MongoDB Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "3.6",
                                "version_value": "3.6.21"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "4.0",
                                "version_value": "4.0.20"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "MongoDB Inc."
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects: MongoDB Inc. MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-185 Incorrect Regular Expression"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.mongodb.org/browse/SERVER-51083",
                  "refsource": "MISC",
                  "url": "https://jira.mongodb.org/browse/SERVER-51083"
                }
              ]
            },
            "source": {
              "discovery": "EXTERNAL"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
        "assignerShortName": "mongodb",
        "cveId": "CVE-2020-7929",
        "datePublished": "2021-03-01T16:05:17.498Z",
        "dateReserved": "2020-01-23T00:00:00.000Z",
        "dateUpdated": "2024-09-16T19:46:52.238Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-7923 (GCVE-0-2020-7923)

    Vulnerability from cvelistv5 โ€“ Published: 2020-08-21 14:25 โ€“ Updated: 2024-09-17 02:27
    VLAI
    Title
    Specific GeoQuery can cause DoS against MongoDB Server
    Summary
    A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator ยท CISA-ADP (v2.0.3)
    Decision recorded 2024-04-22 18:48 UTC
    CWE
    • CWE-755 - Improper Handling of Exceptional Conditions
    References
    Impacted products
    Vendor Product Version
    MongoDB Inc. MongoDB Server Affected: 4.4 , < 4.4.0-rc7 (custom)
    Affected: 4.2 , < 4.2.8 (custom)
    Affected: 4.0 , < 4.0.19 (custom)
    Create a notification for this product.
    mongodb mongodb Affected: 4.4
        cpe:2.3:a:mongodb:mongodb:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2020-08-20 23:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:mongodb:mongodb:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mongodb",
                "vendor": "mongodb",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.4"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-7923",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-22T18:48:55.411971Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-04T17:12:12.302Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T09:48:24.552Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://jira.mongodb.org/browse/SERVER-47773"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "MongoDB Server",
              "vendor": "MongoDB Inc.",
              "versions": [
                {
                  "lessThan": "4.4.0-rc7",
                  "status": "affected",
                  "version": "4.4",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.2.8",
                  "status": "affected",
                  "version": "4.2",
                  "versionType": "custom"
                },
                {
                  "lessThan": "4.0.19",
                  "status": "affected",
                  "version": "4.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2020-08-20T23:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eA user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem\u0027s support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.\u003c/p\u003e"
                }
              ],
              "value": "A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem\u0027s support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-755",
                  "description": "CWE-755 Improper Handling of Exceptional Conditions",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-23T15:13:08.850Z",
            "orgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
            "shortName": "mongodb"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://jira.mongodb.org/browse/SERVER-47773"
            }
          ],
          "source": {
            "defect": [
              "SECURITY-658"
            ],
            "discovery": "INTERNAL"
          },
          "title": "Specific GeoQuery can cause DoS against MongoDB Server",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cna@mongodb.com",
              "DATE_PUBLIC": "2020-08-21T14:40:00.000Z",
              "ID": "CVE-2020-7923",
              "STATE": "PUBLIC",
              "TITLE": "Specific GeoQuery can cause DoS against MongoDB Server"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "MongoDB Server",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "4.4",
                                "version_value": "4.4.0-rc7"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "4.2",
                                "version_value": "4.2.8"
                              },
                              {
                                "version_affected": "\u003c",
                                "version_name": "4.0",
                                "version_value": "4.0.19"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "MongoDB Inc."
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem\u0027s support for geoNear. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.0-rc7; v4.2 versions prior to 4.2.8; v4.0 versions prior to 4.0.19."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-755 Improper Handling of Exceptional Conditions"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://jira.mongodb.org/browse/SERVER-47773",
                  "refsource": "MISC",
                  "url": "https://jira.mongodb.org/browse/SERVER-47773"
                }
              ]
            },
            "source": {
              "defect": [
                "SECURITY-658"
              ],
              "discovery": "INTERNAL"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a39b4221-9bd0-4244-95fc-f3e2e07f1deb",
        "assignerShortName": "mongodb",
        "cveId": "CVE-2020-7923",
        "datePublished": "2020-08-21T14:25:12.201Z",
        "dateReserved": "2020-01-23T00:00:00.000Z",
        "dateUpdated": "2024-09-17T02:27:47.252Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }