CVE-2018-20804: Invariant failure in applyOps
A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects MongoDB Server v4.0 versions prior to 4.0.10 and MongoDB Server v3.6 versions prior to 3.6.13.
Other sources
A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.10; v3.6 versions prior to 3.6.13.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-20804.
What is the title of the vulnerability?
The title of the vulnerability is A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations.
Which software versions are affected by this vulnerability?
MongoDB Server v4.0 versions prior to 4.0.10; v3.6 versions prior to 3.6.13 are affected by this vulnerability.
What is the severity of CVE-2018-20804?
The severity of CVE-2018-20804 is medium with a severity value of 6.5.
How can I fix this vulnerability?
To fix this vulnerability, update MongoDB Server to version 4.0.10 or higher for v4.0 versions, and version 3.6.13 or higher for v3.6 versions.