
We found results for “”
CVE-2025-3084
Good to know:

Date: April 1, 2025
When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0 prior to 6.0.20, MongoDB Server v7.0 prior to 7.0.16 and MongoDB Server v8.0 prior to 8.0.4
Severity Score
Severity Score
Weakness Type (CWE)
Improper Check or Handling of Exceptional Conditions
CWE-703Top Fix

Upgrade Version
Upgrade to version https://github.com/mongodb/mongo.git - r5.0.31;https://github.com/mongodb/mongo.git - r6.0.20;https://github.com/mongodb/mongo.git - r7.0.16;https://github.com/mongodb/mongo.git - r8.0.4
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |