BIT-mongodb-2020-7928

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mongodb/BIT-mongodb-2020-7928.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-mongodb-2020-7928
Aliases
Published
2024-03-06T10:58:33.099Z
Modified
2025-05-20T10:02:07.006Z
Summary
Improper neutralization of null byte leads to read overrun
Details

A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20.

Database specific
{
    "cpes": [
        "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / mongodb

Package

Name
mongodb
Purl
pkg:bitnami/mongodb

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
3.6.0
Fixed
3.6.20
Introduced
4.0.0
Fixed
4.0.20
Introduced
4.2.0
Fixed
4.2.9
Introduced
4.4.0
Fixed
4.4.1
Introduced
4.5.0
Fixed
4.5.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/mongodb/BIT-mongodb-2020-7928.json"