Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KM…
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to …
Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. T…
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathemat…
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue…
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. T…
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting Quer…
A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects Mon…
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch . This …
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript ex…
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which trigger an invariant in the In…
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use the $mod operator to over…
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a spec…
A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the ser…
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the que…
In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops …
Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credent…
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() par…
X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper acces…
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour includi…
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsot…
The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of servic…
An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs ship…
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and becom…
Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.
_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read vi…
The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Servi…
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file…
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol com…
In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote at…