Description
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28858 | A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20. |
References
History
Tue, 17 Sep 2024 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20. | A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20. |
Status: PUBLISHED
Assigner: mongodb
Published:
Updated: 2024-09-17T00:20:37.058Z
Reserved: 2020-01-23T00:00:00.000Z
Link: CVE-2020-7928
No data.
Status : Modified
Published: 2020-11-23T17:15:12.797
Modified: 2024-11-21T05:38:01.733
Link: CVE-2020-7928
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-158
Improper Neutralization of Null Byte or NUL Character
-
CWE-626
Null Byte Interaction Error (Poison Null Byte)
- NVD-CWE-Other
EUVD