Home
HIGH: 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:NHIGH: 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HDefault status
unaffected
8.3.0 (semver) before 8.3.3
affected
8.2.0 (semver) before 8.2.10
affected
8.0.0 (semver) before 8.0.24
affected
7.0.0 (semver) before 7.0.35
affected
Description
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
Problem types
CWE-1287 Improper validation of specified type of input
Product status
8.3.0 (semver) before 8.3.3
8.2.0 (semver) before 8.2.10
8.0.0 (semver) before 8.0.24
7.0.0 (semver) before 7.0.35
Credits
daffainfo (Muhammad Daffa)
References
jira.mongodb.org/browse/SERVER-124959