MongoDB mongo-c-driver
cpe:2.3:a:mongodb:c_driver:*:*:*:*:mongodb:*:*
- >= 1.30.0, < 1.30.6
- >= 2.1.0, < 2.1.2
A vulnerability exists in the MongoDB C Driver's bulk operation functionality, specifically within the `mongoc_bulk_operation_t` component. This issue can lead to reading invalid memory when large options are provided. The vulnerability is present in versions of the MongoDB C Driver prior to 1.30.6 and in the 2.x series prior to 2.1.2.
Exploitation of this vulnerability can cause memory corruption by allowing the bulk operation to read invalid memory locations, potentially leading to undefined behavior or application crashes.
Users can upgrade to MongoDB C Driver version 1.30.6 or 2.1.2, both of which address this vulnerability. Instructions for downloading these versions are available on the MongoDB C Driver GitHub release pages.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.