Security Advisory

CVE-2018-25004

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-03-01 16:15:14
Last updated 2024-11-19 15:42:57
Assigner mongodb
State PUBLISHED

Description

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.