Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-25004

Опубликовано: 01 мар. 2021
Источник: debian
EPSS Низкий

Описание

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mongodbremovedpackage
mongodbend-of-lifestretchpackage

Примечания

  • https://jira.mongodb.org/browse/SERVER-38275

EPSS

Процентиль: 60%
0.01004
Низкий

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 5 лет назад

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

CVSS3: 4.9
redhat
больше 5 лет назад

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

CVSS3: 4.9
nvd
больше 5 лет назад

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

CVSS3: 4.9
github
больше 4 лет назад

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.6; MongoDB Server v3.6 versions prior to 3.6.11.

EPSS

Процентиль: 60%
0.01004
Низкий
Уязвимость CVE-2018-25004