Invariant failure when explaining a find with a UUID
CVE-2018-25004
4.9MEDIUM
Key Information:
- Vendor
MongoDB
- Status
- Vendor
- CVE Published:
- 1 March 2021
What is CVE-2018-25004?
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.
Affected Version(s)
MongoDB Server 3.6 < 3.6.11
MongoDB Server 4.0 < 4.0.6