Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-3104

Опубликовано: 06 дек. 2016
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)mongodbWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)mongodbWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)mongodbWill not fix
Red Hat Enterprise MRG 2mongodbWill not fix
Red Hat OpenShift Enterprise 2mongodbWill not fix
Red Hat OpenStack Platform 8 (Liberty)mongodbWill not fix
Red Hat Satellite 6mongodbWill not fix
Red Hat Software Collectionsrh-mongodb26-mongodbWill not fix
Red Hat Software Collectionsrh-mongodb30upg-mongodbWill not fix
Red Hat Software Collectionsrh-mongodb32-mongodbWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1324496mongodb: Unauthenticated remote DoS via memory exhaustion

EPSS

Процентиль: 83%
0.02489
Низкий

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

CVSS3: 7.5
nvd
больше 9 лет назад

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

CVSS3: 7.5
debian
больше 9 лет назад

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remot ...

CVSS3: 7.5
github
больше 4 лет назад

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

EPSS

Процентиль: 83%
0.02489
Низкий

5 Medium

CVSS2