An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28
References
Link Resource
https://jira.mongodb.org/browse/SERVER-59294 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mongodb

Published: 2022-02-04T00:00:00

Updated: 2024-01-23T16:27:13.617Z

Reserved: 2021-05-05T00:00:00


Link: CVE-2021-32036

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-02-04T23:15:11.490

Modified: 2024-01-23T17:15:08.597


Link: CVE-2021-32036

JSON object: View

cve-icon Redhat Information

No data.

CWE