Search CVE reports


Toggle filters

51 – 60 of 96 results


CVE-2021-32050

Medium priority
Needs evaluation

Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific...

3 affected packages

mongo-c-driver, node-mongodb, php-mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Not affected Not affected Ignored Ignored
node-mongodb Needs evaluation Needs evaluation Needs evaluation Ignored
php-mongodb Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-1409

Medium priority
Not affected

If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2022-24272

Medium priority
Not affected

An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc....

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not affected Not affected
Show less packages

CVE-2021-32040

Medium priority
Vulnerable

It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2022-24795

Medium priority

Some fixes available 6 of 108

yajl-ruby is a C binding to the YAJL JSON parsing and generation library. The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB)...

12 affected packages

yajl, argyll, ruby-yajl, tulip, burp...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
yajl Not affected Fixed Fixed Fixed
argyll Needs evaluation Needs evaluation Needs evaluation Needs evaluation
ruby-yajl Needs evaluation Needs evaluation Needs evaluation Needs evaluation
tulip Not in release Needs evaluation
burp Needs evaluation Needs evaluation Needs evaluation Needs evaluation
centreon-broker
collada2gltf Not in release Needs evaluation Needs evaluation
icinga2 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libbson Needs evaluation
lnav Needs evaluation Needs evaluation Needs evaluation Needs evaluation
php-mongodb Needs evaluation Needs evaluation Needs evaluation Needs evaluation
r-cran-jsonlite Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show all 12 packages Show less packages

CVE-2021-32036

Medium priority
Vulnerable

An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Vulnerable Vulnerable
Show less packages

CVE-2021-20330

Medium priority
Not affected

An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not affected Not affected
Show less packages

CVE-2021-32037

Medium priority
Not affected

An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not affected Not affected
Show less packages

CVE-2021-20333

Medium priority
Vulnerable

Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2021-20329

Low priority
Not affected

Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go object with specific string to potentially inject additional fields...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages