CVE-2021-20326: Specially crafted query may result in a denial of service of mongod
Published Apr 30, 2021
·Updated
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.4.
Other sources
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.4.
Affected Software
1 affected component
MongoDB MongoDB>=4.4.0<4.4.4
Remediation
Patch Available
Event History
Apr 30, 2021
CVE Published
via MITRE·09:10 AM
Data Sourced
via MITRE·09:10 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-20326.
2
What is the severity of CVE-2021-20326?
The severity of CVE-2021-20326 is medium (6.5).
3
What software does CVE-2021-20326 affect?
CVE-2021-20326 affects MongoDB Server v4.4 versions prior to 4.4.4.
4
How can a user trigger the denial of service in CVE-2021-20326?
A user authorized to performing a specific type of find query may trigger a denial of service.
5
Is there a fix available for CVE-2021-20326?
Yes, the fix for CVE-2021-20326 is to update MongoDB Server to version 4.4.4 or later.