CVE-2018-25004

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2018-25004
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-25004.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-25004
Published
2021-03-01T17:15:11Z
Modified
2024-06-06T12:17:10.767957Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events

Affected versions

r4.*

r4.0.0
r4.0.1
r4.0.1-rc0
r4.0.1-rc1
r4.0.2
r4.0.2-rc0
r4.0.3
r4.0.3-rc0
r4.0.4
r4.0.4-rc0
r4.0.4-rc1
r4.0.4-rc2
r4.0.5
r4.0.5-rc0
r4.0.5-rc1
r4.0.6-rc0