Denial of Service when processing malformed Role names
CVE-2020-7925
7.5HIGH
Key Information:
- Vendor
MongoDB
- Status
- Vendor
- CVE Published:
- 23 November 2020
What is CVE-2020-7925?
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.
Affected Version(s)
MongoDB Server 4.2 < 4.2.9
MongoDB Server 4.4 < 4.4.0-rc12