MongoDB Server (mongod) may crash in response to unexpected requests
CVE-2022-24272
6.5MEDIUM
Key Information:
- Vendor
MongoDB
- Status
- Vendor
- CVE Published:
- 21 April 2022
What is CVE-2022-24272?
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
Affected Version(s)
MongoDB Server 5.0 <= 5.0.6