A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.
The product specifies a regular expression in a way that causes data to be improperly matched or compared.
Link | Tags |
---|---|
https://jira.mongodb.org/browse/SERVER-51083 | issue tracking patch vendor advisory |