Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-32036

Опубликовано: 05 фев. 2022
Источник: redhat
CVSS3: 5.4

Описание

An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28

A flaw was found in the MongoDB database when repeatedly invoking the features command. This flaw allows an authenticated attacker without any specific authorizations to repeatedly invoke commands, leading to resource depletion or the generation of high lock contention.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Openshift Data Foundation 4noobaa-core-containerNot affected
Red Hat Openshift Data Foundation 4odf4/mcg-core-rhel9Not affected
Red Hat OpenStack Platform 10 (Newton)mongodbNot affected
Red Hat Satellite 6mongodbNot affected
Red Hat Update Infrastructure 3 for Cloud ProvidersmongodbNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2051953mongodb: Repeatedly invoking the features command at a high volume may lead to resource depletion

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 4 лет назад

An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28

CVSS3: 5.4
nvd
около 4 лет назад

An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28

CVSS3: 5.4
debian
около 4 лет назад

An authenticated user without any specific authorizations may be able ...

CVSS3: 7.1
github
почти 4 года назад

An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions.

5.4 Medium

CVSS3