CVE-2018-25004

Related Vulnerabilities: CVE-2018-25004  

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.6; MongoDB Server v3.6 versions prior to 3.6.11.

Description

The MITRE CVE dictionary describes this issue as:

A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.6; MongoDB Server v3.6 versions prior to 3.6.11.

Additional Information

  • Bugzilla 1934765: CVE-2018-25004 mongodb: Denial of service through generic explain command on a find query
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2018-25004