Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.
The behavior of this function is undefined unless its control parameter is set to a specific value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mongodb | Mongodb | 4.2.0 (including) | 4.2.9 (excluding) |
Mongodb | Mongodb | 4.4.0-rc1 (including) | 4.4.0-rc1 (including) |
Mongodb | Mongodb | 4.4.0-rc10 (including) | 4.4.0-rc10 (including) |
Mongodb | Mongodb | 4.4.0-rc11 (including) | 4.4.0-rc11 (including) |
Mongodb | Mongodb | 4.4.0-rc2 (including) | 4.4.0-rc2 (including) |
Mongodb | Mongodb | 4.4.0-rc3 (including) | 4.4.0-rc3 (including) |
Mongodb | Mongodb | 4.4.0-rc4 (including) | 4.4.0-rc4 (including) |
Mongodb | Mongodb | 4.4.0-rc5 (including) | 4.4.0-rc5 (including) |
Mongodb | Mongodb | 4.4.0-rc6 (including) | 4.4.0-rc6 (including) |
Mongodb | Mongodb | 4.4.0-rc7 (including) | 4.4.0-rc7 (including) |
Mongodb | Mongodb | 4.4.0-rc8 (including) | 4.4.0-rc8 (including) |
Mongodb | Mongodb | 4.4.0-rc9 (including) | 4.4.0-rc9 (including) |
Mongodb | Ubuntu | bionic | * |
Mongodb | Ubuntu | trusty | * |
Mongodb | Ubuntu | trusty/esm | * |
Mongodb | Ubuntu | xenial | * |