Search CVE reports


Toggle filters

41 – 50 of 93 results


CVE-2024-6384

Medium priority
Not affected

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2024-7553

Medium priority
Ignored

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined...

3 affected packages

mongo-c-driver, mongodb, php-mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Ignored Ignored Ignored
mongodb Not in release Not in release Ignored Ignored
php-mongodb Ignored Ignored Ignored Ignored
Show less packages

CVE-2024-6375

Medium priority
Not affected

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2024-3374

Medium priority
Not affected

An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2024-3372

Medium priority
Not affected

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2024-1351

Medium priority
Vulnerable

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2023-0437

Medium priority
Not affected

When calling bson_utf8_validateĀ on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0.

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2021-32050

Medium priority
Needs evaluation

Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific...

3 affected packages

mongo-c-driver, node-mongodb, php-mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongo-c-driver Not affected Not affected Ignored Ignored
node-mongodb Needs evaluation Needs evaluation Needs evaluation Ignored
php-mongodb Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-1409

Medium priority
Not affected

If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that...

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not in release Not in release Not affected Not affected
Show less packages

CVE-2022-24272

Medium priority
Not affected

An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc....

1 affected package

mongodb

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mongodb Not affected Not affected
Show less packages