← Back to CVE List

CVE-2021-20330

Published: 2021-12-15T13:15Z
Last Modified: 2024-11-21T05:46Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt