CVE Vulnerabilities

CVE-2020-7925

Undefined Behavior for Input to API

Published: Nov 23, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.

Weakness

The behavior of this function is undefined unless its control parameter is set to a specific value.

Affected Software

NameVendorStart VersionEnd Version
MongodbMongodb4.2.0 (including)4.2.9 (excluding)
MongodbMongodb4.4.0-rc1 (including)4.4.0-rc1 (including)
MongodbMongodb4.4.0-rc10 (including)4.4.0-rc10 (including)
MongodbMongodb4.4.0-rc11 (including)4.4.0-rc11 (including)
MongodbMongodb4.4.0-rc2 (including)4.4.0-rc2 (including)
MongodbMongodb4.4.0-rc3 (including)4.4.0-rc3 (including)
MongodbMongodb4.4.0-rc4 (including)4.4.0-rc4 (including)
MongodbMongodb4.4.0-rc5 (including)4.4.0-rc5 (including)
MongodbMongodb4.4.0-rc6 (including)4.4.0-rc6 (including)
MongodbMongodb4.4.0-rc7 (including)4.4.0-rc7 (including)
MongodbMongodb4.4.0-rc8 (including)4.4.0-rc8 (including)
MongodbMongodb4.4.0-rc9 (including)4.4.0-rc9 (including)
MongodbUbuntubionic*
MongodbUbuntufocal*
MongodbUbuntutrusty*
MongodbUbuntutrusty/esm*
MongodbUbuntuupstream*
MongodbUbuntuxenial*

References