IM
IronMonkey Threat Research

CVE-2020-7923 MEDIUM

Published: 2020-08-21 | Last Modified: 2024-11-21 | Status: Modified

Description

A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.

Additional Descriptions (1)

Un usuario autorizado para llevar a cabo consultas en la base de datos puede causar una denegación de servicio al emitir consultas especialmente diseñadas, que violan una invariante en el soporte del subsistema de consultas para geoNear. Este problema afecta a: MongoDB Server de MongoDB Inc versiones v4.4 anteriores a 4.4.0-rc7; versiones v4.2 anteriores a 4.2.8; versiones v4.0 anteriores a 4.0.19

CVSS Metrics

Base Score: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 3.6

Base Score: 4.0 (MEDIUM)

AV:N/AC:L/Au:S/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationSINGLE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-755
[email protected] Primary
en CWE-755

Affected Products

Vendor Product Version Update Type
mongodb mongodb * <built-in method update of dict object at 0x717bdaaa54c0> Application
mongodb mongodb * <built-in method update of dict object at 0x717bdb98e300> Application
mongodb mongodb * <built-in method update of dict object at 0x717bdb98fbc0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

References

Notification
Message here