CVE-2016-3104

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.
References
Link Resource
http://www.securityfocus.com/bid/94929 Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1324496 Issue Tracking Third Party Advisory VDB Entry
https://jira.mongodb.org/browse/SERVER-24378 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:2.6.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-04-14 18:59

Updated : 2023-12-10 12:01


NVD link : CVE-2016-3104

Mitre link : CVE-2016-3104

CVE.ORG link : CVE-2016-3104


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-400

Uncontrolled Resource Consumption