Логотип exploitDog
bind: "CVE-2025-6709"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-6709"

Количество 7

Количество 7

ubuntu логотип

CVE-2025-6709

около 2 месяцев назад

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-6709

около 2 месяцев назад

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-6709

около 2 месяцев назад

The MongoDB Server is susceptible to a denial of service vulnerability ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-5cq2-33xv-h4mm

около 1 месяца назад

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-07725

около 2 месяцев назад

Уязвимость реализации протокола аутентификации OIDC сервера системы управления базами данных MongoDB, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250806-09

5 дней назад

Множественные уязвимости mongodb-org

CVSS3: 7.7
EPSS: Низкий
redos логотип

ROS-20250806-08

5 дней назад

Множественные уязвимости mongodb-org

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-6709

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-6709

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-6709

The MongoDB Server is susceptible to a denial of service vulnerability ...

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-5cq2-33xv-h4mm

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2025-07725

Уязвимость реализации протокола аутентификации OIDC сервера системы управления базами данных MongoDB, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20250806-09

Множественные уязвимости mongodb-org

CVSS3: 7.7
5 дней назад
redos логотип
ROS-20250806-08

Множественные уязвимости mongodb-org

CVSS3: 7.7
5 дней назад

Уязвимостей на страницу