CVE Published: 21/04/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022 Source: mongodb |
Vendor: MongoDB Inc. |
Product: MongoDB Server Status : PUBLISHED
CVE-2022-24272 Description
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H