An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions.
References
Link | Resource |
---|---|
https://jira.mongodb.org/browse/SERVER-59294 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-02-04 15:15
Updated : 2022-02-09 11:24
NVD link : CVE-2021-32036
Mitre link : CVE-2021-32036
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
mongodb
- mongodb