[SERVER-50170] Fix server selection failure on mongos Created: 07/Aug/20  Updated: 29/Oct/23  Resolved: 17/Aug/20

Status: Closed
Project: Core Server
Component/s: None
Affects Version/s: None
Fix Version/s: 4.4.1

Type: Task Priority: Major - P3
Reporter: Lamont Nelson Assignee: Lamont Nelson
Resolution: Fixed Votes: 0
Labels: KP44
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Backports
Related
related to SERVER-57136 Incompatible wire version error on se... Closed
related to SERVER-57451 TopologyDescription::clone should mak... Closed
Backwards Compatibility: Fully Compatible
Backport Requested:
v4.4
Participants:

 Description   
CVE-2020-7926

Title: Specific query can cause a DoS against MongoDB Server

Description:

A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem. This issue affects: MongoDB Server version 4.4 prior to 4.4.1. Versions before 4.4 are not affected. 

CVSS score: 6.5

Using the following scoring metrics:
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CWE: 'CWE-755: Improper Handling of Exceptional Conditions'.

Affected versions:

This issue affects - MongoDB Inc. MongoDB Server:

v4.4 versions prior to 4.4.1

Due to a bug in the query planner it's possible to trip this invariant for certain types of queries.



 Comments   
Comment by Githook User [ 17/Aug/20 ]

Author:

{'name': 'LaMont Nelson', 'email': 'lamont.nelson@mongodb.com', 'username': 'lamontnelson'}

Message: SERVER-50170 fix max staleness read preference parameter for server selection

(cherry picked from commit 75f7184eafa78006a698cda4c4adfb57f1290047)
Branch: v4.4
https://github.com/mongodb/mongo/commit/859ec65c84f201e7aa687865633a2fa34e318174

Comment by Githook User [ 14/Aug/20 ]

Author:

{'name': 'LaMont Nelson', 'email': 'lamont.nelson@mongodb.com', 'username': 'lamontnelson'}

Message: SERVER-50170 fix max staleness read preference parameter for server selection
Branch: master
https://github.com/mongodb/mongo/commit/75f7184eafa78006a698cda4c4adfb57f1290047

Generated at Thu Feb 08 05:21:58 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.