[SERVER-68062] Multi-stage aggregations that use $geoNear may violate constraints. Created: 14/Jul/22  Updated: 29/Oct/23  Resolved: 15/Jul/22

Status: Closed
Project: Core Server
Component/s: Aggregation Framework
Affects Version/s: 6.0.0-rc13
Fix Version/s: 6.0.1, 6.1.0-rc0

Type: Bug Priority: Critical - P2
Reporter: Mihai Andrei Assignee: Kyle Suarez
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified

Issue Links:
Backports
Problem/Incident
is caused by SERVER-64662 Investigate and fix test failure in j... Closed
Related
Backwards Compatibility: Fully Compatible
Operating System: ALL
Backport Requested:
v6.0
Sprint: QE 2022-07-25
Participants:

 Comments   
Comment by Githook User [ 15/Jul/22 ]

Author:

{'name': 'Kyle Suarez', 'email': 'kyle.suarez@mongodb.com', 'username': 'ksuarz'}

Message: SERVER-68062 permit DocumentSourceGeoNearCursor to have secondary collections

(cherry picked from commit 3bf33a7f67667dbe5c1785c2d6a55a19cd17fb4e)
Branch: v6.0
https://github.com/mongodb/mongo/commit/7765a294e9b9a1234164cee10218592e3027fcee

Comment by Kyle Suarez [ 15/Jul/22 ]

Filed and linked TIG-4267 to help prevent these bugs in the future.

Comment by Githook User [ 15/Jul/22 ]

Author:

{'name': 'Kyle Suarez', 'email': 'kyle.suarez@mongodb.com', 'username': 'ksuarz'}

Message: SERVER-68062 permit DocumentSourceGeoNearCursor to have secondary collections
Branch: master
https://github.com/mongodb/mongo/commit/3bf33a7f67667dbe5c1785c2d6a55a19cd17fb4e

Comment by Boris Sieklik [ 15/Jul/22 ]

kyle.suarez@mongodb.com  thanks for helping with this. I am happy for you to re-use the title from this ticket as a CVE title. Once you finish the required information (there are other things needed for CVE ticket like title and affected versions), we check the content anyway and can recommend changes as needed . For now we just need that key info and we will ask for details over Slack. Hope this helps!

 

I am CCing karman.liu@mongodb.com who is also a CVE expert so she can assist more if needed. 

Comment by Boris Sieklik [ 15/Jul/22 ]

mihai.andrei@mongodb.com let me know if you need some assistance from us in regards to raising a CVE. CC karman.liu@mongodb.com 

Generated at Thu Feb 08 06:09:46 UTC 2024 using Jira 9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66.