Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v8v4-4v92-48h2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.0-rc12; v4.2 versions prior to 4.2.9.

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.0-rc12; v4.2 versions prior to 4.2.9.

EPSS

Процентиль: 82%
0.01665
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-475

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.

CVSS3: 7.5
redhat
около 5 лет назад

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.

CVSS3: 7.5
nvd
около 5 лет назад

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.

CVSS3: 7.5
debian
около 5 лет назад

Incorrect validation of user input in the role name parser may lead to ...

EPSS

Процентиль: 82%
0.01665
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-475