CVE-2018-20803: Infinite loop in aggregation expression
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects MongoDB Server v4.0 versions prior to 4.0.5; MongoDB Server v3.6 versions prior to 3.6.10 and MongoDB Server v3.4 versions prior to 3.4.19.
Other sources
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathematics processing while retaining locks. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.5; v3.6 versions prior to 3.6.10; v3.4 versions prior to 3.4.19.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-20803?
CVE-2018-20803 is a vulnerability in MongoDB Server versions prior to 4.0.5, 3.6 versions prior to 3.6.10, and 3.4 versions prior to 3.4.19, that allows a user authorized to perform database queries to trigger denial of service by issuing specially crafted queries.
How does CVE-2018-20803 work?
CVE-2018-20803 works by causing an indefinite loop in the mathematics processing of MongoDB Server, while retaining locks, which leads to denial of service.
What is the severity of CVE-2018-20803?
CVE-2018-20803 has a severity rating of 6.5, which is considered medium.
What software versions are affected by CVE-2018-20803?
CVE-2018-20803 affects MongoDB Server versions prior to 4.0.5, 3.6 versions prior to 3.6.10, and 3.4 versions prior to 3.4.19.
How can I mitigate CVE-2018-20803?
To mitigate CVE-2018-20803, it is recommended to update MongoDB Server to version 4.0.5, 3.6.10, or 3.4.19 or later.