Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.
Una comprobación inapropiada de la entrada del usuario en el analizador de nombres de funciones puede conllevar al uso de memoria no inicializada, permitiendo a un atacante no autenticado usar una petición especialmente diseñada para causar una denegación de servicio. Este problema afecta a: MongoDB Server de MongoDB Inc versiones v4.4 anteriores a 4.4.0-rc12; versiones v4.2 anteriores a 4.2.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
AV:N/AC:L/Au:N/C:N/I:N/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-475
|
| [email protected] | Primary |
en
CWE-20
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| mongodb | mongodb | * | <built-in method update of dict object at 0x717bdaaa67c0> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdaabf4c0> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdaaa7580> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdaabd400> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdaaa7b80> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdaaa54c0> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdaabdfc0> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdc85c7c0> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdaaa5580> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdaaa5cc0> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdb7c3fc0> | Application |
| mongodb | mongodb | 4.4.0 | <built-in method update of dict object at 0x717bdaaa7e00> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc1:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc10:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc11:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc2:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc3:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc4:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc5:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc6:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc7:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc8:*:*:*:*:*:* |
| Yes | cpe:2.3:a:mongodb:mongodb:4.4.0:rc9:*:*:*:*:*:* |