When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0 prior to 6.0.20, MongoDB Server v7.0 prior to 7.0.16 and MongoDB Server v8.0 prior to 8.0.4
History

Tue, 01 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 11:30:00 +0000

Type Values Removed Values Added
Description When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0 prior to 6.0.20, MongoDB Server v7.0 prior to 7.0.16 and MongoDB Server v8.0 prior to 8.0.4
Title MongoDB Server may crash due to improper validation of explain command
First Time appeared Mongodb
Mongodb mongodb
Weaknesses CWE-703
CPEs cpe:2.3:a:mongodb:mongodb:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.14:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.15:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.16:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.17:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.18:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.19:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.20:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.21:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.23:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.24:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.25:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.26:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.27:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.28:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.29:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.30:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.14:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.15:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.16:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.17:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.18:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.19:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.14:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.15:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:8.0.3:*:*:*:*:*:*:*
Vendors & Products Mongodb
Mongodb mongodb
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2025-04-01T13:10:04.793Z

Reserved: 2025-04-01T09:07:06.147Z

Link: CVE-2025-3084

cve-icon Vulnrichment

Updated: 2025-04-01T13:09:59.215Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-01T12:15:16.037

Modified: 2025-04-01T20:26:11.547

Link: CVE-2025-3084

cve-icon Redhat

No data.