Логотип exploitDog
bind:"GHSA-5cq2-33xv-h4mm" OR bind:"CVE-2025-6709"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-5cq2-33xv-h4mm" OR bind:"CVE-2025-6709"

Количество 7

Количество 7

github логотип

GHSA-5cq2-33xv-h4mm

4 месяца назад

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-6709

4 месяца назад

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-6709

4 месяца назад

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-6709

4 месяца назад

The MongoDB Server is susceptible to a denial of service vulnerability ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-07725

4 месяца назад

Уязвимость реализации протокола аутентификации OIDC сервера системы управления базами данных MongoDB, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250806-09

2 месяца назад

Множественные уязвимости mongodb-org

CVSS3: 7.7
EPSS: Низкий
redos логотип

ROS-20250806-08

2 месяца назад

Множественные уязвимости mongodb-org

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5cq2-33xv-h4mm

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-6709

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-6709

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to 8.0.5. The same issue affects MongoDB Server v6.0 versions prior to 6.0.21, but an attacker can only induce denial of service after authenticating.

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-6709

The MongoDB Server is susceptible to a denial of service vulnerability ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
fstec логотип
BDU:2025-07725

Уязвимость реализации протокола аутентификации OIDC сервера системы управления базами данных MongoDB, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
4 месяца назад
redos логотип
ROS-20250806-09

Множественные уязвимости mongodb-org

CVSS3: 7.7
2 месяца назад
redos логотип
ROS-20250806-08

Множественные уязвимости mongodb-org

CVSS3: 7.7
2 месяца назад

Уязвимостей на страницу