CVE-2022-24272

An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-63968 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

11 May 2022, 20:14

Type Values Removed Values Added
CWE CWE-617
First Time Mongodb
Mongodb mongodb
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 6.5
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
References (MISC) https://jira.mongodb.org/browse/SERVER-63968 - (MISC) https://jira.mongodb.org/browse/SERVER-63968 - Issue Tracking, Patch, Vendor Advisory

11 May 2022, 15:15

Type Values Removed Values Added
References
  • (MISC) https://jira.mongodb.org/browse/SERVER-63968 -
Summary ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage. An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.

22 Apr 2022, 16:15

Type Values Removed Values Added
References
  • {'url': 'https://jira.mongodb.org/browse/SERVER-63968', 'name': 'https://jira.mongodb.org/browse/SERVER-63968', 'tags': [], 'refsource': 'MISC'}
Summary An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6. ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.

21 Apr 2022, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-21 11:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-24272

Mitre link : CVE-2022-24272

CVE.ORG link : CVE-2022-24272


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-617

Reachable Assertion