MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-db/mongodb. | Oct 30, 2017 | Mar 30, 2015 |
| Mongodb | — | Upgrade MongoDB to version 2.4.12Upgrade to the latest version of MongoDB | Oct 31, 2019 | Mar 30, 2015 |
| Ubuntu | — | Upgrade mongodb (Ubuntu Pro) | Jun 26, 2025 | Mar 30, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub