MongoDB NoSQL Database
By the Year
In 2023 there have been 0 vulnerabilities in MongoDB . Last year MongoDB had 4 security vulnerabilities published. Right now, MongoDB is on track to have less security vulnerabilities in 2023 than it did last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2023 | 0 | 0.00 |
2022 | 4 | 6.65 |
2021 | 6 | 6.03 |
2020 | 5 | 6.46 |
2019 | 2 | 5.65 |
2018 | 0 | 0.00 |
It may take a day or so for new MongoDB vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent MongoDB Security Vulnerabilities
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database
CVE-2022-24272
6.5 - Medium
- April 21, 2022
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
assertion failure
It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator
CVE-2021-32040
7.5 - High
- April 12, 2022
It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB versions prior to 5.0.4, 4.4.11, 4.2.16.
Memory Corruption
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention
CVE-2021-32036
7.1 - High
- February 04, 2022
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions.
Allocation of Resources Without Limits or Throttling
Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file
CVE-2021-32039
5.5 - Medium
- January 20, 2022
Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS Code in a binary file. These credentials may be used by malicious attackers to perform unauthorized actions. This vulnerability affects all MongoDB Extension for VS Code including and prior to version 0.7.0
Insufficiently Protected Credentials
An attacker with basic CRUD permissions on a replicated collection
CVE-2021-20330
6.5 - Medium
- December 15, 2021
An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.25; MongoDB Server v4.2 versions prior to 4.2.14; MongoDB Server v4.4 versions prior to 4.4.6.
Improper Input Validation
An authorized user may trigger an invariant
CVE-2021-32037
6.5 - Medium
- November 24, 2021
An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard. Usually, the requests are sent via mongos and special privileges are required in order to know the address of the shards and to log in to the shards of an auth enabled environment.
assertion failure
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split
CVE-2021-20333
5.3 - Medium
- July 23, 2021
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21; MongoDB Server v4.2 versions prior to 4.2.10;
Output Sanitization
A user authorized to performing a specific type of find query may trigger a denial of service
CVE-2021-20326
6.5 - Medium
- April 30, 2021
A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.4.
Incorrect Permission Assignment for Critical Resource
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query
CVE-2018-25004
4.9 - Medium
- March 01, 2021
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.6; MongoDB Server v3.6 versions prior to 3.6.11.
Improper Input Validation
A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex
CVE-2020-7929
6.5 - Medium
- March 01, 2021
A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects: MongoDB Inc. MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries
CVE-2020-7928
6.5 - Medium
- November 23, 2020
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.1; v4.2 versions prior to 4.2.9; v4.0 versions prior to 4.0.20; v3.6 versions prior to 3.6.20.
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory
CVE-2020-7925
7.5 - High
- November 23, 2020
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.0-rc12; v4.2 versions prior to 4.2.9.
Improper Input Validation
A user authorized to perform database queries may cause denial of service by issuing a specially crafted query
CVE-2020-7926
6.5 - Medium
- November 23, 2020
A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem. This issue affects: MongoDB Server version 4.4 prior to 4.4.1. Versions before 4.4 are not affected.
Improper Handling of Exceptional Conditions
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries
CVE-2020-7923
6.5 - Medium
- August 21, 2020
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects: MongoDB Inc. MongoDB Server v4.4 versions prior to 4.4.0-rc7; v4.2 versions prior to 4.2.8; v4.0 versions prior to 4.0.19.
Improper Handling of Exceptional Conditions
Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action
CVE-2020-7921
5.3 - Medium
- May 06, 2020
Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects: MongoDB Inc. MongoDB Server 4.2 versions prior to 4.2.3; 4.0 versions prior to 4.0.15; 4.3 versions prior to 4.3.3; 3.6 versions prior to 3.6.18.
AuthZ
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts
CVE-2019-2389
4.2 - Medium
- August 30, 2019
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.11; v3.6 versions prior to 3.6.14; v3.4 versions prior to 3.4.22.
Improper Input Validation
After user deletion in MongoDB Server the improper invalidation of authorization sessions
CVE-2019-2386
7.1 - High
- August 06, 2019
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.9; v3.6 versions prior to 3.6.13; v3.4 versions prior to 3.4.22.
AuthZ
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which
CVE-2013-1892
- October 01, 2013
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.
Improper Input Validation
bson/_cbsonmodule.c in the mongo-python-driver (aka
CVE-2013-2132
- August 15, 2013
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."