Vulnerability Description
A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem. This issue affects MongoDB Server v4.4 versions prior to 4.4.1. Versions before 4.4 are not affected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Mongodb | >= 4.4.0, < 4.4.1 |
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/SERVER-50170Issue TrackingVendor Advisory
- https://jira.mongodb.org/browse/SERVER-50170Issue TrackingVendor Advisory
FAQ
What is CVE-2020-7926?
CVE-2020-7926 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem. This issue affects MongoDB...
How severe is CVE-2020-7926?
CVE-2020-7926 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7926?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb Mongodb.