Sploitus

CVE-2022-24272

2 known exploits for CVE-2022-24272

An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.

Affected products
Mongodb Server, Mongodb
Mongodb
≤ 5.0.6
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.9% (57th percentile)
Weakness
CWE-617
NVD status
Modified
Published
2022-04-21
CVE-2022-24272 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2022-24272

Proof-of-concept code and exploit modules indexed by Sploitus