Vulnerabilities > CVE-2021-32037 - Reachable Assertion vulnerability in Mongodb 5.0.0/5.0.1/5.0.2

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
mongodb
CWE-617

Summary

An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the address of the shards and to log in to the shards of an auth enabled environment. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.2.

Vulnerable Configurations

Part Description Count
Application
Mongodb
16

Common Weakness Enumeration (CWE)