First published: Thu Apr 21 2022(Updated: )
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
Credit: cna@mongodb.com
Affected Software | Affected Version | How to fix |
---|---|---|
MongoDB MongoDB | >=5.0.0<=5.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24272 is a vulnerability that allows an authenticated user to trigger an invariant assertion during command dispatch in MongoDB Server versions prior to and including v5.0.6, leading to denial of service or server crash.
CVE-2022-24272 affects MongoDB Server v5.0 versions, prior to and including v5.0.6.
CVE-2022-24272 has a severity rating of 6.5 (medium).
An authenticated user can exploit CVE-2022-24272 by triggering an invariant assertion during command dispatch in MongoDB Server.
To mitigate CVE-2022-24272, it is recommended to upgrade MongoDB Server to a version that is higher than v5.0.6.