CVE-2019-20924

MEDIUM

MongoDB 4.2.0-4.2.1 - Denial of Service via IndexBoundsBuilder Invariant

Title source: llm
STIX 2.1

Description

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which trigger an invariant in the IndexBoundsBuilder. This issue affects MongoDB Server v4.2 versions prior to 4.2.2.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://jira.mongodb.org/browse/SERVER-44377

Scores

CVSS v3 6.5
EPSS 0.0128
EPSS Percentile 66.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-754 CWE-394
Status published
Products (1)
mongodb/mongodb 4.2.0 - 4.2.2
Published Nov 23, 2020
Tracked Since Feb 18, 2026