Vulnerability Description
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify memory.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 3.4.0, < 3.4.10 |
References
- http://www.securityfocus.com/bid/101689Third Party AdvisoryVDB Entry
- https://jira.mongodb.org/browse/SERVER-31273Issue TrackingVendor Advisory
- http://www.securityfocus.com/bid/101689Third Party AdvisoryVDB Entry
- https://jira.mongodb.org/browse/SERVER-31273Issue TrackingVendor Advisory
FAQ
What is CVE-2017-15535?
CVE-2017-15535 is a vulnerability with a CVSS score of 9.1 (CRITICAL). MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabl...
How severe is CVE-2017-15535?
CVE-2017-15535 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-15535?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.