Vulnerabilities > Mongodb

DATE CVE VULNERABILITY TITLE RISK
2021-03-01 CVE-2018-25004 Improper Input Validation vulnerability in Mongodb
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query.
network
low complexity
mongodb CWE-20
4.9
2021-03-01 CVE-2020-7929 Unspecified vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex.
network
low complexity
mongodb
6.5
2021-02-25 CVE-2021-20328 Improper Certificate Validation vulnerability in multiple products
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate.
high complexity
mongodb quarkus CWE-295
6.8
2021-02-25 CVE-2021-20327 Improper Certificate Validation vulnerability in Mongodb Libmongocrypt 1.2.0
A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate.
high complexity
mongodb CWE-295
6.8
2021-02-11 CVE-2021-20335 Cleartext Transmission of Sensitive Information vulnerability in Mongodb OPS Manager
For MongoDB Ops Manager versions prior to and including 4.2.24 with multiple OM application servers, that have SSL turned on for their MongoDB processes, the upgrade to MongoDB Ops Manager versions prior to and including 4.4.12 triggers a bug where Automation thinks SSL is being turned off, and can disable SSL temporarily for members of the cluster.
low complexity
mongodb CWE-319
4.6
2020-11-24 CVE-2019-20925 Incorrect Comparison vulnerability in Mongodb
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory.
network
low complexity
mongodb CWE-697
7.5
2020-11-23 CVE-2020-7927 Unspecified vulnerability in Mongodb OPS Manager
Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege.
network
low complexity
mongodb
6.5
2020-11-23 CVE-2018-20803 Infinite Loop vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks.
network
low complexity
mongodb CWE-835
6.5
2020-11-23 CVE-2020-7928 Unspecified vulnerability in Mongodb
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries.
network
low complexity
mongodb
6.5
2020-11-23 CVE-2019-2393 Use After Free vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations.
network
low complexity
mongodb CWE-416
6.5