CVE-2021-32036
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/02/2022
Last modified:
17/09/2024
Description
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
5.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | 2.0.0 (including) | 4.2.18 (excluding) |
| cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | 4.4.0 (including) | 4.4.10 (excluding) |
| cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | 5.0.0 (including) | 5.0.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



