First published: Mon Nov 23 2020(Updated: )
A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem. This issue affects MongoDB Server v4.4 versions prior to 4.4.1. Versions before 4.4 are not affected.
Credit: cna@mongodb.com cna@mongodb.com
Affected Software | Affected Version | How to fix |
---|---|---|
MongoDB MongoDB | >=4.4.0<4.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-7926 is a vulnerability in MongoDB Server version 4.4 prior to 4.4.1 that allows a user authorized to perform database queries to cause denial of service by issuing a specially crafted query.
CVE-2020-7926 affects MongoDB Server version 4.4 prior to 4.4.1.
The severity rating of CVE-2020-7926 is medium with a CVSS score of 6.5.
This vulnerability can be exploited by a user authorized to perform database queries who issues a specially crafted query that violates an invariant in the server selection subsystem.
No, MongoDB Server version 4.4.1 is not affected by CVE-2020-7926. Versions before 4.4 are also not affected.