Description
An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.
Remediation
References
Related Vulnerabilities
MySQL CVE-2023-22064 Vulnerability (CVE-2023-22064)
WordPress Plugin Ivory Search-WordPress Search Cross-Site Scripting (4.5.10)
WordPress Plugin Malware Finder Cross-Site Scripting (1.1)
WordPress Plugin WP Photo Album Plus Cross-Site Scripting (5.0.2)
phpBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-0471)