漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
Denial of Service and Data Integrity vulnerability in features command
漏洞信息
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28
漏洞信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
漏洞
不加限制或调节的资源分配
漏洞
MongoDB Server 安全漏洞
漏洞信息
Mongodb Server是美国Mongodb公司的一套开源的NoSQL数据库。该数据库提供面向集合的存储、动态查询、数据复制及自动故障转移等功能。 MongoDB Server 存在安全漏洞,没有任何特定授权的经过身份验证的用户可能能够重复调用 features 命令,其中大量可能导致资源耗尽或产生高锁争用。这可能会导致拒绝服务,并且在极少数情况下可能会导致 id 字段冲突。
漏洞信息
N/A
漏洞
N/A