Description
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-13786 | A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11. |
References
History
Tue, 19 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 17 Sep 2024 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11. | A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11. |
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2024-11-19T15:42:57.505Z
Reserved: 2021-01-29T00:00:00.000Z
Link: CVE-2018-25004
Updated: 2024-08-05T12:26:39.551Z
Status : Modified
Published: 2021-03-01T17:15:11.717
Modified: 2024-11-21T04:03:20.397
Link: CVE-2018-25004
OpenCVE Enrichment
No data.
Weaknesses
EUVD