CVE-2020-7929: Specially crafted regex query can cause DoS
A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.
Other sources
A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects: MongoDB Inc. MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-7929.
What software versions are affected by this vulnerability?
This vulnerability affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.
What is the severity of CVE-2020-7929?
The severity of CVE-2020-7929 is medium (6.5).
How can this vulnerability be exploited?
A user authorized to perform database queries can trigger denial of service by issuing a specially crafted query containing a type of regex.
Is there a fix available for this vulnerability?
Yes, the fix for this vulnerability is to update MongoDB Server to version 3.6.21 or 4.0.20.