CVE-2022-24272

Source
https://cve.org/CVERecord?id=CVE-2022-24272
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24272.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-24272
Aliases
Downstream
Published
2022-04-21T10:45:11.960Z
Modified
2026-07-15T01:48:57.835126745Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
MongoDB Server (mongod) may crash in response to unexpected requests
Details

An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.

Database specific
{
    "cwe_ids": [
        "CWE-617"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24272.json",
    "cna_assigner": "mongodb",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "5.0"
                },
                {
                    "last_affected": "5.0.6"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/mongodb/mongo

Affected ranges

Type
GIT
Repo
https://github.com/mongodb/mongo
Events
Database specific
{
    "cpe": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "last_affected": "5.0.6"
        }
    ]
}

Affected versions

r5.*
r5.0.0
r5.0.1
r5.0.1-rc0
r5.0.2
r5.0.2-rc0
r5.0.3
r5.0.3-rc0
r5.0.3-rc1
r5.0.3-rc2
r5.0.4
r5.0.4-rc0
r5.0.5
r5.0.5-rc0
r5.0.6
r5.0.6-rc0
r5.0.6-rc1
r5.0.6-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24272.json"