CVE-2017-15535: Critical severity MongoDB MongoDB vulnerability
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15535?
CVE-2017-15535 is classified as a medium severity vulnerability that could lead to denial of service or memory modification.
How do I fix CVE-2017-15535?
To fix CVE-2017-15535, ensure that the networkMessageCompressors setting is disabled in your MongoDB configuration.
Which versions of MongoDB are affected by CVE-2017-15535?
CVE-2017-15535 affects MongoDB versions 3.4.x before 3.4.10 and 3.5.x-development.
What type of attack can exploit CVE-2017-15535?
CVE-2017-15535 can be exploited by a malicious attacker to launch denial-of-service attacks or to modify the memory of the MongoDB server.
Is the networkMessageCompressors setting enabled by default in MongoDB?
No, the networkMessageCompressors setting is disabled by default in MongoDB.