Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Denial of Service and Data Integrity vulnerability in features command
Vulnerability Description
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
MongoDB Server 安全漏洞
Vulnerability Description
Mongodb Server是美国Mongodb公司的一套开源的NoSQL数据库。该数据库提供面向集合的存储、动态查询、数据复制及自动故障转移等功能。 MongoDB Server 存在安全漏洞,没有任何特定授权的经过身份验证的用户可能能够重复调用 features 命令,其中大量可能导致资源耗尽或产生高锁争用。这可能会导致拒绝服务,并且在极少数情况下可能会导致 id 字段冲突。
CVSS Information
N/A
Vulnerability Type
N/A