An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions.
References
| Link | Resource |
|---|---|
| https://jira.mongodb.org/browse/SERVER-59294 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-02-04 23:15
Updated : 2022-02-09 19:24
NVD link : CVE-2021-32036
Mitre link : CVE-2021-32036
JSON object : View
Products Affected
mongodb
- mongodb
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
