Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3and MongoDB Server v3.6 versions prior to 3.6.18.
[
{
"signature_type": "Function",
"target": {
"file": "src/mongo/db/query/index_bounds_builder.cpp",
"function": "IndexBoundsBuilder::translate"
},
"deprecated": false,
"digest": {
"length": 10021.0,
"function_hash": "78486403470517513513507602625303794039"
},
"source": "https://github.com/mongodb/mongo/commit/5547f61d0abc1f81cf160f3693f741b8ce889084",
"id": "CVE-2020-7921-0c8641fe",
"signature_version": "v1"
},
{
"signature_type": "Line",
"target": {
"file": "src/mongo/s/chunk_manager.cpp"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"216047242538325188510789508059390863951",
"19134725029155574891208209763213239283",
"280350291644563600163399192870586213469",
"158471671787918280684621999039749177392",
"319252374832009046210058763182627393369",
"35133896178452706910239926455607150103",
"269683469505268152573654287813534155434",
"45894333507022972339205895791765184874",
"189017555455735371341324486703990093029",
"195789163172404835977769385756468802230"
]
},
"source": "https://github.com/mongodb/mongo/commit/6874650b362138df74be53d366bbefc321ea32d4",
"id": "CVE-2020-7921-7f0cfdc5",
"signature_version": "v1"
},
{
"signature_type": "Line",
"target": {
"file": "src/mongo/db/index_builds_coordinator.cpp"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"319627655637418790389422297517391553563",
"189784691795828970654973910444557199215",
"121517871084720856882554087334652170679",
"62740642666871806115401491643036783593"
]
},
"source": "https://github.com/mongodb/mongo/commit/eca08e963444d77209f093a6137f5d70f7519e21",
"id": "CVE-2020-7921-a8bb5b65",
"signature_version": "v1"
},
{
"signature_type": "Function",
"target": {
"file": "src/mongo/db/index_builds_coordinator.cpp",
"function": "IndexBuildsCoordinator::_runIndexBuildInner"
},
"deprecated": false,
"digest": {
"length": 2121.0,
"function_hash": "77658919316696371001354544066792061409"
},
"source": "https://github.com/mongodb/mongo/commit/eca08e963444d77209f093a6137f5d70f7519e21",
"id": "CVE-2020-7921-aa954409",
"signature_version": "v1"
},
{
"signature_type": "Line",
"target": {
"file": "src/mongo/db/query/index_bounds_builder.cpp"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"183325986263730029783145769233746546977",
"123381212820886298349966924986002522067",
"111994179737223563519244919762904925280",
"20045680424455326026444037119399315791",
"178162148596604817171712189158769295367",
"175833461177246951838067897461225808701",
"226627054187368723268332052001371174536",
"80356908345382160467524557309268499395",
"262715759425002269926591737891800697712"
]
},
"source": "https://github.com/mongodb/mongo/commit/5547f61d0abc1f81cf160f3693f741b8ce889084",
"id": "CVE-2020-7921-dd7a0311",
"signature_version": "v1"
},
{
"signature_type": "Function",
"target": {
"file": "src/mongo/s/chunk_manager.cpp",
"function": "ChunkManager::findIntersectingChunk"
},
"deprecated": false,
"digest": {
"length": 893.0,
"function_hash": "610635629547753280401429845588597963"
},
"source": "https://github.com/mongodb/mongo/commit/6874650b362138df74be53d366bbefc321ea32d4",
"id": "CVE-2020-7921-e602df99",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-7921.json"