MongoDB
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*
- >= 5.0, < 5.0.31
- >= 6.0, < 6.0.20
- >= 7.0, < 7.0.16
A denial-of-service vulnerability has been identified in MongoDB components 'mongos' across multiple versions. Specifically crafted wire protocol messages can cause 'mongos' to crash during command validation. This issue arises without the need for an authenticated connection. Affected versions include MongoDB 5.0 prior to 5.0.31, MongoDB 6.0 prior to 6.0.20, and MongoDB 7.0 prior to 7.0.16.
Exploitation of this vulnerability leads to a crash of the 'mongos' process, causing a denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.