CVE-2020-7928: Improper neutralization of null byte leads to read overrun
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20.
Other sources
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.1; v4.2 versions prior to 4.2.9; v4.0 versions prior to 4.0.20; v3.6 versions prior to 3.6.20.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-7928?
CVE-2020-7928 is a vulnerability that allows a user authorized to perform database queries to trigger a read overrun and access arbitrary memory by issuing specially crafted queries.
Which software versions are affected by CVE-2020-7928?
CVE-2020-7928 affects MongoDB Inc. MongoDB Server versions v4.4 prior to 4.4.1, v4.2 prior to 4.2.9, v4.0 prior to 4.0.20, and v3.6 prior to 3.6.20.
What is the severity of CVE-2020-7928?
CVE-2020-7928 has a severity rating of 6.5 (Medium).
How can I fix the CVE-2020-7928 vulnerability?
To fix the CVE-2020-7928 vulnerability, update MongoDB Server to version 4.4.1 for v4.4, 4.2.9 for v4.2, 4.0.20 for v4.0, and 3.6.20 for v3.6.
Where can I find more information about CVE-2020-7928?
More information about CVE-2020-7928 can be found at the following reference: [https://jira.mongodb.org/browse/SERVER-49404](https://jira.mongodb.org/browse/SERVER-49404).