CVE-2022-24272
MongoDB Server (mongod) may crash in response to unexpected requests
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An authenticated user may trigger an invariant assertion during command dispatch due to incorrect validation on the $external database. This may result in mongod denial of service or server crash. This issue affects: MongoDB Inc. MongoDB Server v5.0 versions, prior to and including v5.0.6.
Un usuario autenticado puede desencadenar una aserción invariante durante el envío de comandos debido a una validación incorrecta en la base de datos $external. Esto puede dar lugar a una denegación de servicio mongod o a la caída del servidor. Este problema afecta a: MongoDB Inc. las versiones del servidor MongoDB v5.0, anteriores a la v5.0.6 inclusive
WordPress International SMS for Contact Form 7 Integration plugin version 1.2 suffers from a cross site request forgery vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-31 CVE Reserved
- 2022-02-14 CVE Published
- 2023-11-12 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-617: Reachable Assertion
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://jira.mongodb.org/browse/SERVER-63968 | 2022-05-11 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mongodb Search vendor "Mongodb" | Mongodb Search vendor "Mongodb" for product "Mongodb" | >= 5.0.0 <= 5.0.6 Search vendor "Mongodb" for product "Mongodb" and version " >= 5.0.0 <= 5.0.6" | - |
Affected
|