Vulnerability Description
mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | 2.4.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94929Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1324496Issue TrackingThird Party AdvisoryVDB Entry
- https://jira.mongodb.org/browse/SERVER-24378Vendor Advisory
- http://www.securityfocus.com/bid/94929Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1324496Issue TrackingThird Party AdvisoryVDB Entry
- https://jira.mongodb.org/browse/SERVER-24378Vendor Advisory
FAQ
What is CVE-2016-3104?
CVE-2016-3104 is a vulnerability with a CVSS score of 7.5 (HIGH). mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representat...
How severe is CVE-2016-3104?
CVE-2016-3104 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-3104?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.