6.5
CVSSv3

CVE-2021-20330

Published: 15/12/2021 Updated: 23/01/2024
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions before 4.0.27; MongoDB Server v4.2 versions before 4.2.16; MongoDB Server v4.4 versions before 4.4.9.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mongodb mongodb

Vendor Advisories

An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries This issue affects MongoDB Server v40 versions prior to 4025; MongoDB Server v42 versions prior to 4214; MongoDB Server v44 versions prior to 446 ...