A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript exceptions containing types intended to be scoped to the Javascript engine's internals. This issue affects MongoDB Server v4.0 versions prior to 4.0.7.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb mongodb Server
|
|
| CPEs | cpe:2.3:a:mongodb:mongodb_server:4.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Mongodb mongodb Server
|
|
| Metrics |
ssvc
|
Mon, 16 Sep 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript exceptions containing types intended to be scoped to the Javascript engine's internals. This issue affects MongoDB Server v4.0 versions prior to 4.0.7. | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript exceptions containing types intended to be scoped to the Javascript engine's internals. This issue affects MongoDB Server v4.0 versions prior to 4.0.7. |
Status: PUBLISHED
Assigner: mongodb
Published: 2020-11-23T15:30:20.507Z
Updated: 2024-09-16T17:03:47.113Z
Reserved: 2020-10-06T00:00:00.000Z
Link: CVE-2019-20923
Updated: 2024-08-05T03:00:19.094Z
Status : Modified
Published: 2020-11-23T16:15:12.807
Modified: 2024-11-21T04:39:42.017
Link: CVE-2019-20923