Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10.
2021-07-23T12:15:08.453
2024-11-21T05:46:24.000
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mongodb | mongodb | < 3.6.20 | Yes |
| Application | mongodb | mongodb | < 4.0.21 | Yes |
| Application | mongodb | mongodb | < 4.2.10 | Yes |