CVE-2018-25004

All FrameworksMongoDBCWE-20CVE-2018-25004

CVE-2018-25004

State: PUBLISHED · Published: 2021-03-01 · Updated: 2024-11-19 · Assigner: mongodb
Description
A user authorized to performing a specific type of query may trigger a denial of service by issuing a generic explain command on a find query. This issue affects MongoDB Server v4.0 versions prior to 4.0.6 and MongoDB Server v3.6 versions prior to 3.6.11.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2018/25xxx/CVE-2018-25004.json