CVE-2021-32036

An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28
References
Link Resource
https://jira.mongodb.org/browse/SERVER-59294 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

23 Jan 2024, 17:15

Type Values Removed Values Added
Summary (en) An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. (en) An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28

09 Feb 2022, 19:24

Type Values Removed Values Added
References (MISC) https://jira.mongodb.org/browse/SERVER-59294 - (MISC) https://jira.mongodb.org/browse/SERVER-59294 - Issue Tracking, Vendor Advisory
CWE CWE-770
CVSS v2 : unknown
v3 : unknown
v2 : 5.5
v3 : 7.1
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
First Time Mongodb
Mongodb mongodb

04 Feb 2022, 23:28

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-04 23:15

Updated : 2024-01-23 17:15


NVD link : CVE-2021-32036

Mitre link : CVE-2021-32036

CVE.ORG link : CVE-2021-32036


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-770

Allocation of Resources Without Limits or Throttling