Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-7923

Опубликовано: 24 апр. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.

A flaw was found in mongodb. A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. The highest threat from this vulnerability is to system availability.

Отчет

Red Hat Satellite 6.6 onward does not ship the MongoDB package; however, the product consumes MongoDB from Red Hat Software Collections (RHSCL) for Red Hat Enterprise Linux. Satellite has no plans to update to a version of MongoDB released with a Server Side Public License (SSPL) which includes all versions released after October 16, 2018. Refer to this article for more information: https://access.redhat.com/articles/5767021 Red Hat Update Infrastructure 3 ships an affected version of mongodb, however it does not use GeoQuery and it is not vulnerable to this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2mongodbNot affected
Red Hat OpenStack Platform 10 (Newton)mongodbOut of support scope
Red Hat Satellite 6mongodbWill not fix
Red Hat Software Collectionsrh-mongodb34-mongodbWill not fix
Red Hat Software Collectionsrh-mongodb36-mongodbWill not fix
Red Hat Update Infrastructure 3 for Cloud ProvidersmongodbFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20

EPSS

Процентиль: 63%
0.00441
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.

CVSS3: 6.5
nvd
больше 5 лет назад

A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.

CVSS3: 6.5
debian
больше 5 лет назад

A user authorized to perform database queries may cause denial of serv ...

CVSS3: 6.5
github
больше 3 лет назад

A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects: MongoDB Inc. MongoDB Server v4.5 versions prior to 4.5.1; v4.4 versions prior to 4.4.0-rc7; v4.2 versions prior to 4.2.8; v4.0 versions prior to 4.0.19.

EPSS

Процентиль: 63%
0.00441
Низкий

6.5 Medium

CVSS3