Denial of Service when processing malformed Role names
Published Nov 23, 2020
7.5
HIGHCVSS 3.1
EPSS 1.69%
Description
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.
Affected products
-
Affected
- ≥ 4.2, < 4.2.9
- ≥ 4.4, < 4.4.0-rc12
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| MongoDB Inc. | MongoDB Server | unaffected | Affected
|
- ≥ 4.2.0 · < 4.2.9
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
- 4.4.0
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
mongodb
Not affected
Red Hat OpenStack Platform 10 (Newton)
mongodb
Out of support scope
Red Hat Software Collections
rh-mongodb36-mongodb
Not affected
Red Hat Update Infrastructure 3 for Cloud Providers
mongodb
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | mongodb | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | mongodb | Out of support scope | n/a |
| Red Hat Software Collections | rh-mongodb36-mongodb | Not affected | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | mongodb | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2020-7925 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1900860 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28855 Advisory
- https://jira.mongodb.org/browse/SERVER-49142 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7925
- https://www.cve.org/CVERecord?id=CVE-2020-7925
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-7925 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1900860 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28855 | Advisory | |
| https://jira.mongodb.org/browse/SERVER-49142 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7925 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-7925 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data