CVE-2020-7921

Source
https://cve.org/CVERecord?id=CVE-2020-7921
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-7921.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-7921
Aliases
Downstream
Published
2020-05-06T15:15:11.880Z
Modified
2026-02-03T07:13:30.435393Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3and MongoDB Server v3.6 versions prior to 3.6.18.

References

Affected packages

Git / github.com/mongodb/mongo

Affected versions

r3.*
r3.6.0
r3.6.1
r3.6.1-rc0
r3.6.1-rc1
r3.6.10
r3.6.10-rc0
r3.6.10-rc1
r3.6.11
r3.6.11-rc0
r3.6.11-rc1
r3.6.11-rc2
r3.6.12
r3.6.12-rc0
r3.6.12-rc1
r3.6.13
r3.6.13-rc0
r3.6.13-rc1
r3.6.14
r3.6.14-rc0
r3.6.15
r3.6.15-rc0
r3.6.15-rc1
r3.6.16
r3.6.16-rc0
r3.6.17
r3.6.17-rc0
r3.6.2
r3.6.2-rc0
r3.6.3
r3.6.3-rc0
r3.6.3-rc1
r3.6.4
r3.6.4-rc0
r3.6.5
r3.6.5-rc0
r3.6.6
r3.6.6-rc0
r3.6.7
r3.6.7-rc0
r3.6.7-rc1
r3.6.8
r3.6.8-rc0
r3.6.8-rc1
r3.6.9
r3.6.9-rc0
r4.*
r4.0.0
r4.0.1
r4.0.1-rc0
r4.0.1-rc1
r4.0.10
r4.0.10-rc0
r4.0.10-rc1
r4.0.11
r4.0.11-rc0
r4.0.12
r4.0.12-rc0
r4.0.12-rc1
r4.0.12-rc2
r4.0.13
r4.0.13-rc0
r4.0.14
r4.0.14-rc0
r4.0.14-rc1
r4.0.2
r4.0.2-rc0
r4.0.3
r4.0.3-rc0
r4.0.4
r4.0.4-rc0
r4.0.4-rc1
r4.0.4-rc2
r4.0.5
r4.0.5-rc0
r4.0.5-rc1
r4.0.6
r4.0.6-rc0
r4.0.6-rc1
r4.0.7
r4.0.7-rc0
r4.0.7-rc1
r4.0.8
r4.0.8-rc0
r4.0.9
r4.0.9-rc0
r4.2.0
r4.2.1
r4.2.1-rc0
r4.2.2
r4.2.2-rc0
r4.2.2-rc1
r4.2.3-rc0
r4.3.0
r4.3.1
r4.3.2

Database specific

vanir_signatures
[
    {
        "signature_type": "Function",
        "target": {
            "file": "src/mongo/db/query/index_bounds_builder.cpp",
            "function": "IndexBoundsBuilder::translate"
        },
        "deprecated": false,
        "digest": {
            "length": 10021.0,
            "function_hash": "78486403470517513513507602625303794039"
        },
        "source": "https://github.com/mongodb/mongo/commit/5547f61d0abc1f81cf160f3693f741b8ce889084",
        "id": "CVE-2020-7921-0c8641fe",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "src/mongo/s/chunk_manager.cpp"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "216047242538325188510789508059390863951",
                "19134725029155574891208209763213239283",
                "280350291644563600163399192870586213469",
                "158471671787918280684621999039749177392",
                "319252374832009046210058763182627393369",
                "35133896178452706910239926455607150103",
                "269683469505268152573654287813534155434",
                "45894333507022972339205895791765184874",
                "189017555455735371341324486703990093029",
                "195789163172404835977769385756468802230"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/6874650b362138df74be53d366bbefc321ea32d4",
        "id": "CVE-2020-7921-7f0cfdc5",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "src/mongo/db/index_builds_coordinator.cpp"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "319627655637418790389422297517391553563",
                "189784691795828970654973910444557199215",
                "121517871084720856882554087334652170679",
                "62740642666871806115401491643036783593"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/eca08e963444d77209f093a6137f5d70f7519e21",
        "id": "CVE-2020-7921-a8bb5b65",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "src/mongo/db/index_builds_coordinator.cpp",
            "function": "IndexBuildsCoordinator::_runIndexBuildInner"
        },
        "deprecated": false,
        "digest": {
            "length": 2121.0,
            "function_hash": "77658919316696371001354544066792061409"
        },
        "source": "https://github.com/mongodb/mongo/commit/eca08e963444d77209f093a6137f5d70f7519e21",
        "id": "CVE-2020-7921-aa954409",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "src/mongo/db/query/index_bounds_builder.cpp"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "183325986263730029783145769233746546977",
                "123381212820886298349966924986002522067",
                "111994179737223563519244919762904925280",
                "20045680424455326026444037119399315791",
                "178162148596604817171712189158769295367",
                "175833461177246951838067897461225808701",
                "226627054187368723268332052001371174536",
                "80356908345382160467524557309268499395",
                "262715759425002269926591737891800697712"
            ]
        },
        "source": "https://github.com/mongodb/mongo/commit/5547f61d0abc1f81cf160f3693f741b8ce889084",
        "id": "CVE-2020-7921-dd7a0311",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "src/mongo/s/chunk_manager.cpp",
            "function": "ChunkManager::findIntersectingChunk"
        },
        "deprecated": false,
        "digest": {
            "length": 893.0,
            "function_hash": "610635629547753280401429845588597963"
        },
        "source": "https://github.com/mongodb/mongo/commit/6874650b362138df74be53d366bbefc321ea32d4",
        "id": "CVE-2020-7921-e602df99",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-7921.json"