Описание
The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON object in the column name in an insert command, which triggers a buffer over-read.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | mongodb | Will not fix | ||
| Red Hat OpenShift Enterprise 2 | mongodb | Not affected | ||
| Red Hat OpenStack Platform 3 | mongodb | Affected | ||
| Red Hat Software Collections | mongodb24-mongodb | Not affected | ||
| Red Hat Subscription Asset Manager | mongodb | Affected | ||
| RHUI for RHEL 6 | mongodb | Will not fix | ||
| OpenStack 4 for RHEL 6 | mongodb | Fixed | RHSA-2014:0230 | 04.03.2014 |
| Red Hat Enterprise MRG 2 | condor | Fixed | RHSA-2014:0440 | 28.04.2014 |
| Red Hat Enterprise MRG 2 | cumin | Fixed | RHSA-2014:0440 | 28.04.2014 |
| Red Hat Enterprise MRG 2 | mongodb | Fixed | RHSA-2014:0440 | 28.04.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.8 Medium
CVSS2
Связанные уязвимости
The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON object in the column name in an insert command, which triggers a buffer over-read.
The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON object in the column name in an insert command, which triggers a buffer over-read.
The default configuration for MongoDB before 2.3.2 does not validate o ...
The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON object in the column name in an insert command, which triggers a buffer over-read.
EPSS
5.8 Medium
CVSS2