Beveiligingsadvies

CVE-2020-7925

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-11-23 14:50:12
Laatst bijgewerkt 2024-09-17 00:20:32
Toegewezen door mongodb
CVSS-score 7.5
Status PUBLISHED

Beschrijving

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.