MongoDB Server
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*
- >= 6.0, < 6.0.23
- >= 7.0, < 7.0.20
- >= 8.0, < 8.0.9
A denial-of-service vulnerability has been identified in the mongos component of MongoDB Server. This issue arises from improper handling of incomplete data, which can cause mongos to become unresponsive to new connections. The vulnerability affects MongoDB Server versions 6.0 prior to 6.0.23, 7.0 prior to 7.0.20, and 8.0 prior to 8.0.9. It specifically impacts sharded clusters configured with load balancer support for mongos, using HAProxy on designated ports.
Exploitation of this vulnerability can lead to mongos becoming unresponsive to new connections, causing a denial-of-service condition in MongoDB sharded clusters.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.