An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28
References
Link | Resource |
---|---|
https://jira.mongodb.org/browse/SERVER-59294 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
17 Sep 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28 |
23 Jan 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary | An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28 |
09 Feb 2022, 19:24
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 5.5
v3 : 7.1 |
CWE | CWE-770 | |
References | (MISC) https://jira.mongodb.org/browse/SERVER-59294 - Issue Tracking, Vendor Advisory | |
CPE | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* |
04 Feb 2022, 23:28
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-02-04 23:15
Updated : 2024-09-17 05:15
NVD link : CVE-2021-32036
Mitre link : CVE-2021-32036
CVE.ORG link : CVE-2021-32036
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-770
Allocation of Resources Without Limits or Throttling