CVE-2020-7923: Specific GeoQuery can cause DoS against MongoDB Server
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.
Other sources
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.0-rc7; v4.2 versions prior to 4.2.8; v4.0 versions prior to 4.0.19.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-7923?
CVE-2020-7923 is a vulnerability that allows a user authorized to perform database queries to cause denial of service by issuing specially crafted queries on MongoDB Server versions prior to 4.4.0-rc7.
How does CVE-2020-7923 affect MongoDB Server?
CVE-2020-7923 affects MongoDB Server versions prior to 4.4.0-rc7.
What is the severity of CVE-2020-7923?
The severity of CVE-2020-7923 is medium with a severity value of 6.5.
How can I fix CVE-2020-7923?
To fix CVE-2020-7923, it is recommended to upgrade MongoDB Server to version 4.4.0-rc7 or later.
Where can I find more information about CVE-2020-7923?
You can find more information about CVE-2020-7923 on the MongoDB Jira page: https://jira.mongodb.org/browse/SERVER-47773