CVE-2020-7925

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mongodbCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
mongodbmongodb
4.2.0 ≤
𝑥
< 4.2.9
mongodbmongodb
4.4.0:rc1
mongodbmongodb
4.4.0:rc10
mongodbmongodb
4.4.0:rc11
mongodbmongodb
4.4.0:rc2
mongodbmongodb
4.4.0:rc3
mongodbmongodb
4.4.0:rc4
mongodbmongodb
4.4.0:rc5
mongodbmongodb
4.4.0:rc6
mongodbmongodb
4.4.0:rc7
mongodbmongodb
4.4.0:rc8
mongodbmongodb
4.4.0:rc9
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mongodb
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
dne
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage