[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Unexpected status code or return value vulnerability in MongoDB - CVE-2018-20802

ID: oval:org.secpod.oval:def:67419Date: (C)2020-11-25   (M)2024-01-29
Class: VULNERABILITYFamily: windows




The host is installed with MongoDB 3.6 before 3.6.9 or 4.0 before 4.0.3 and is prone to an unexpected status code or return value vulnerability. A flaw is present in the application which fails to handle specially crafted queries with compound indexes affecting QueryPlanner. Successful exploitation can cause denial of service.

Platform:
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 8.1
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012
Microsoft Windows 7
Microsoft Windows 10
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Product:
MongoDB
Reference:
CVE-2018-20802
CVE    1
CVE-2018-20802

© SecPod Technologies