First published: Mon Nov 23 2020(Updated: )
A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects MongoDB Server v4.0 versions prior to 4.0.10 and MongoDB Server v3.6 versions prior to 3.6.13.
Credit: cna@mongodb.com cna@mongodb.com
Affected Software | Affected Version | How to fix |
---|---|---|
MongoDB MongoDB | >=3.6.0<3.6.13 | |
MongoDB MongoDB | >=4.0.0<4.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-20804.
The title of the vulnerability is A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations.
MongoDB Server v4.0 versions prior to 4.0.10; v3.6 versions prior to 3.6.13 are affected by this vulnerability.
The severity of CVE-2018-20804 is medium with a severity value of 6.5.
To fix this vulnerability, update MongoDB Server to version 4.0.10 or higher for v4.0 versions, and version 3.6.13 or higher for v3.6 versions.