Denial of Service Vulnerability in MongoDB BSON Ruby by Moped
CVE-2015-4411
7.5HIGH
What is CVE-2015-4411?
The Moped::BSON::ObjecId.legal? method in the mongoid/moped library, prior to version 3.0.4, is susceptible to crafted input that could lead to resource exhaustion. This vulnerability allows remote attackers to exploit the method, resulting in a denial of service by consuming worker resources. This was reported as a result of an incomplete fix related to a previous vulnerability (CVE-2015-4410).