Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5ggp-wm87-2p6g

Опубликовано: 01 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0 versions prior to 7.0.16

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0 versions prior to 7.0.16

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-248

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0 versions prior to 7.0.16

CVSS3: 7.5
nvd
3 месяца назад

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0 versions prior to 7.0.16

CVSS3: 7.5
debian
3 месяца назад

Specifically crafted MongoDB wire protocol messages can cause mongos t ...

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость утилиты для обработки фрагментов Mongos системы управления базами данных MongoDB, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.1
redos
около 2 месяцев назад

Множественные уязвимости mongodb-org

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-248