SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-32036

This may result in denial of service and in rare cases could result in id field collisions.

HIGH 7.1EPSS 1.03%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.03%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28

CVSS 3.1
7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
EPSS
1.03% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-770
Affected
mongodb/mongodb
Source
cna@mongodb.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.