CVE-2020-7925: Denial of Service when processing malformed Role names
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.
Other sources
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.0-rc12; v4.2 versions prior to 4.2.9.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
CVE-2020-7925
What is the severity of CVE-2020-7925?
The severity of CVE-2020-7925 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2020-7925?
MongoDB Server v4.4 versions prior to 4.4.0-rc12 and v4.2 versions between 4.2.0 and 4.2.9 are affected by CVE-2020-7925.
How can an unauthenticated attacker exploit CVE-2020-7925?
An unauthenticated attacker can exploit CVE-2020-7925 by using a specially crafted request to cause a denial of service.
Is there a fix available for CVE-2020-7925?
Yes, a fix is available for CVE-2020-7925. MongoDB Server v4.4.0-rc12 and v4.2.9 include the necessary patches to address this vulnerability.