Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.142841
Category:Denial of Service
Title:MongoDB 3.4 < 3.4.22, 3.6 < 3.6.14, 4.0 < 4.0.11, 4.1 < 4.1.14 DoS Vulnerability - Linux
Summary:MongoDB is prone to a denial of service vulnerability.
Description:Summary:
MongoDB is prone to a denial of service vulnerability.

Vulnerability Insight:
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init
scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user
stops the MongoDB process via SysV init.

Affected Software/OS:
MongoDB versions 3.4 prior to 3.4.22, 3.6 prior to 3.6.14, 4.0 prior to
4.0.11 and 4.1 prior to 4.1.14.

Solution:
Update to version 3.4.22, 3.6.14, 4.0.11, 4.1.14 or later.

CVSS Score:
1.9

CVSS Vector:
AV:L/AC:M/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-2389
https://jira.mongodb.org/browse/SERVER-40563
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.