CVE-2013-3969
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 10.11% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- mongodb/mongodb
- Source
- cve@mitre.org
References
- http://blog.scrt.ch/2013/06/04/mongodb-rce-by-databasespraying/
- http://secunia.com/advisories/54170Vendor Advisory
- http://www.mongodb.org/about/alerts/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/07/30/10
- https://jira.mongodb.org/browse/SERVER-9878
- http://blog.scrt.ch/2013/06/04/mongodb-rce-by-databasespraying/
- http://secunia.com/advisories/54170Vendor Advisory
- http://www.mongodb.org/about/alerts/Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/07/30/10
- https://jira.mongodb.org/browse/SERVER-9878
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.