CVE-2019-2393: Crash while joining collections with $lookup
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13 and MongoDB Server v3.6 versions prior to 3.6.15.
Other sources
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. This issue affects: MongoDB Inc. MongoDB Server v4.2 versions prior to 4.2.1; v4.0 versions prior to 4.0.13; v3.6 versions prior to 3.6.15.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-2393?
CVE-2019-2393 is a vulnerability that allows a user with database query authorization to trigger a denial of service attack by issuing specially crafted queries in MongoDB Server.
Which versions of MongoDB Server are affected by CVE-2019-2393?
CVE-2019-2393 affects MongoDB Server v4.2 versions prior to 4.2.1, v4.0 versions prior to 4.0.13, and v3.6 versions prior to 3.6.15.
How does CVE-2019-2393 affect MongoDB Server?
CVE-2019-2393 allows a user with database query authorization to cause a denial of service by using $lookup and collations in specially crafted queries.
What is the severity of CVE-2019-2393?
CVE-2019-2393 has a severity rating of 6.5 (medium).
How can I fix CVE-2019-2393?
To fix CVE-2019-2393, MongoDB Server users should upgrade to version 4.2.1, 4.0.13, or 3.6.15 depending on their current version.