Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-25004

Опубликовано: 01 мар. 2021
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

An improper input validation flaw causing a denial-of-service found in MongoDB. An attacker can perform a specific type of query which issues a generic explain command on a find query causing denial-of-service. The highest threat from this vulnerability is to the system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)mongodbOut of support scope
Red Hat OpenStack Platform 10 (Newton)mongodbOut of support scope
Red Hat Software Collectionsrh-mongodb36-mongodbWill not fix
Red Hat Update Infrastructure 3 for Cloud ProvidersmongodbWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1934765mongodb: Denial of service through generic explain command on a find query

EPSS

Процентиль: 63%
0.00437
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 5 лет назад

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

CVSS3: 4.9
nvd
почти 5 лет назад

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.

CVSS3: 4.9
debian
почти 5 лет назад

A user authorized to performing a specific type of query may trigger a ...

CVSS3: 4.9
github
больше 3 лет назад

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.6; MongoDB Server v3.6 versions prior to 3.6.11.

EPSS

Процентиль: 63%
0.00437
Низкий

4.9 Medium

CVSS3