Vulnerability index

Browse CVEs

158 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2024-7553 Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Win… MongoDB 1.18.1 / 1.26.2+ Fix from $1,9502024-08-07 HIGH 7.5 CVE-2024-6382 Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected appl… Rust Driver 2.8.2+ Fix from $1,9502024-07-02 MEDIUM 5.3 CVE-2024-6381 The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a … Libbson 1.26.2+ Fix from $1,6002024-07-02 CRITICAL 9.8 CVE-2024-6376 MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass'… Compass 1.42.2+ Fix from $2,3002024-07-01 MEDIUM 6.5 CVE-2024-6375 A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to ei… MongoDB 5.0.22 / 6.0.11+ Fix from $1,6002024-07-01 HIGH 8.1 CVE-2024-5629 An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exce… Pymongo 4.6.3+ Fix from $1,9502024-06-05 HIGH 7.5 CVE-2024-3372 Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and m… MongoDB 5.0.25 / 6.0.14+ Fix from $1,9502024-05-14 MEDIUM 5.3 CVE-2024-3374 An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object… MongoDB after 6.0.5 Fix from $1,6002024-05-14 MEDIUM 6.8 CVE-2024-3371 MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, … Compass 1.42.1+ Fix from $1,6002024-04-24 CRITICAL 9.8 CVE-2024-1351 Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect… MongoDB 4.4.29 / 5.0.25+ Fix from $2,3002024-03-07 HIGH 7.5 CVE-2023-0437 When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affe… C Driver 1.25.0+ Fix from $1,9502024-01-12 HIGH 7.5 CVE-2023-0436 The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets … Atlas Kubernetes Operator 1.7.1+ Fix from $1,9502023-11-07 HIGH 7.5 CVE-2021-32050 Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The pu… C\+\+ 1.1.1 / 1.9.2+ Fix from $1,9502023-08-29 HIGH 7.5 CVE-2023-1409 If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to wor… MongoDB 4.4.23 / 6.0.7+ Fix from $1,9502023-08-23 HIGH 7.2 CVE-2023-4009 In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admi… Ops Manager Server 5.0.22 / 6.0.17+ Fix from $1,9502023-08-08 MEDIUM 5.3 CVE-2023-0342 MongoDB Ops Manager Diagnostics Archive may not redact sensitive PEM key file password app settings. Archives do not include the PEM files themselves… Ops Manager Server 5.0.21 / 6.0.12+ Fix from $1,6002023-06-09 HIGH 7.2 CVE-2022-48282 Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitrary code to be executed which … C\# Driver 2.19.0+ Fix from $1,9502023-02-21 MEDIUM 6.5 CVE-2022-24272 An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may resu… MongoDB after 5.0.6 Fix from $1,6002022-04-21 HIGH 7.5 CVE-2021-32040 It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the… MongoDB 4.2.16 / 4.4.11+ Fix from $1,9502022-04-12 HIGH 7.1 CVE-2021-32036 An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to re… MongoDB 4.2.18 / 4.4.10+ Fix from $1,9502022-02-04 MEDIUM 5.5 CVE-2021-32039 Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These … MongoDB after 0.7.0 Fix from $1,6002022-01-20 MEDIUM 6.5 CVE-2021-20330 An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in … MongoDB 4.0.25 / 4.2.14+ Fix from $1,6002021-12-15 MEDIUM 6.5 CVE-2021-32037 An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard… MongoDB after 5.0.2 Fix from $1,6002021-11-24 MEDIUM 5.3 CVE-2021-20333 Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issu… MongoDB 3.6.20 / 4.0.21+ Fix from $1,6002021-07-23 MEDIUM 6.5 CVE-2021-20329 Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A malicious user could use a Go… Go Driver after 1.5.0 Fix from $1,6002021-06-10 MEDIUM 6.5 CVE-2021-20326 A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoDB Server v4.4 versions prior … MongoDB 4.4.4+ Fix from $1,6002021-04-30 MEDIUM 6.5 CVE-2020-7924 Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping … Database Tools 0.6.0 / 3.6.21+ Fix from $1,6002021-04-12 HIGH 7.8 CVE-2021-20334 A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges … Compass 1.25.0+ Fix from $1,9502021-04-06 MEDIUM 6.5 CVE-2020-7929 A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue af… MongoDB 3.6.21 / 4.0.20+ Fix from $1,6002021-03-01 MEDIUM 6.8 CVE-2021-20327 A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerab… Libmongocrypt Mitigation only Fix from $1,6002021-02-25