<!-- 
RSS generated by JIRA (9.7.1#970001-sha1:2222b88b221c4928ef0de3161136cc90c8356a66) at Thu Feb 08 04:44:40 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>MongoDB Jira</title>
    <link>https://jira.mongodb.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.7.1</version>
        <build-number>970001</build-number>
        <build-date>13-04-2023</build-date>
    </build-info>


<item>
            <title>[SERVER-36993] mongod crash:  Invariant failure indexedOr src/mongo/db/query/index_tag.cpp 237</title>
                <link>https://jira.mongodb.org/browse/SERVER-36993</link>
                <project id="10000" key="SERVER">Core Server</project>
                    <description>&lt;div class=&quot;panel&quot; style=&quot;background-color: #eeeeee;border-color: #cccccc;border-width: 1px;&quot;&gt;&lt;div class=&quot;panelHeader&quot; style=&quot;border-bottom-width: 1px;border-bottom-color: #cccccc;background-color: #6cb33f;&quot;&gt;&lt;b&gt;CVE-2018-20802&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;panelContent&quot; style=&quot;background-color: #eeeeee;&quot;&gt;
&lt;p&gt;&lt;b&gt;Title:&lt;/b&gt;&#160;Post-auth queries on compound index may crash mongod&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Description:&lt;/b&gt;&lt;br/&gt;
 A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting QueryPlanner. This issue affects: MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.3; v3.6 versions prior to 3.6.9.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;CVSS score&lt;/b&gt;:&lt;br/&gt;
 This issue&apos;s CVSS:3.1 severity is scored at 6.5 using the following scoring metrics:&lt;br/&gt;
 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H&lt;/p&gt;

&lt;p&gt;&lt;b&gt;Affected versions:&lt;/b&gt;&lt;br/&gt;
 MongoDB Inc. MongoDB Server v4.0 versions prior to 4.0.3; v3.6 versions prior to 3.6.9.&lt;/p&gt;

&lt;p&gt;&lt;b&gt;CWE&lt;/b&gt;: CWE-394: Unexpected Status Code or Return Value&lt;/p&gt;
&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;&#8212;&lt;br/&gt;
 Opening to discuss the security impact of &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-36993&quot; title=&quot;mongod crash:  Invariant failure indexedOr src/mongo/db/query/index_tag.cpp 237&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-36993&quot;&gt;&lt;del&gt;SERVER-36993&lt;/del&gt;&lt;/a&gt;, which affects 3.6.3 and later. This issue was externally identified and reported.&lt;/p&gt;

&lt;p&gt;I believe this exploit can used in a denial of service attack against atlas free tier.&lt;/p&gt;</description>
                <environment></environment>
        <key id="599689">SERVER-36993</key>
            <summary>mongod crash:  Invariant failure indexedOr src/mongo/db/query/index_tag.cpp 237</summary>
                <type id="1" iconUrl="https://jira.mongodb.org/secure/viewavatar?size=xsmall&amp;avatarId=14703&amp;avatarType=issuetype">Bug</type>
                                            <priority id="2" iconUrl="https://jira.mongodb.org/images/icons/priorities/critical.svg">Critical - P2</priority>
                        <status id="6" iconUrl="https://jira.mongodb.org/images/icons/statuses/closed.png" description="The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.">Closed</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="13201">Fixed</resolution>
                                        <assignee username="david.storch@mongodb.com">David Storch</assignee>
                                    <reporter username="travis@bryx.com">Travis Brown</reporter>
                        <labels>
                    </labels>
                <created>Wed, 5 Sep 2018 13:50:06 +0000</created>
                <updated>Sun, 29 Oct 2023 22:28:27 +0000</updated>
                            <resolved>Fri, 14 Sep 2018 16:07:31 +0000</resolved>
                                    <version>3.6.7</version>
                                    <fixVersion>3.6.9</fixVersion>
                    <fixVersion>4.0.3</fixVersion>
                    <fixVersion>4.1.4</fixVersion>
                                    <component>Aggregation Framework</component>
                                        <votes>0</votes>
                                    <watches>11</watches>
                                                                                                                <comments>
                            <comment id="2006782" author="xgen-internal-githook" created="Tue, 18 Sep 2018 17:16:34 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;David Storch&apos;, &apos;email&apos;: &apos;david.storch@10gen.com&apos;, &apos;username&apos;: &apos;dstorch&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-36993&quot; title=&quot;mongod crash:  Invariant failure indexedOr src/mongo/db/query/index_tag.cpp 237&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-36993&quot;&gt;&lt;del&gt;SERVER-36993&lt;/del&gt;&lt;/a&gt; Fix crash due to incorrect $or pushdown for indexed $expr.&lt;/p&gt;

&lt;p&gt;(cherry picked from commit 0aebf209b1467df188b8915d507fc6a2dcf80ef8)&lt;br/&gt;
Branch: v3.6&lt;br/&gt;
&lt;a href=&quot;https://github.com/mongodb/mongo/commit/2b4634bb6512c5345de2ab8f698a687c6cec9973&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/mongodb/mongo/commit/2b4634bb6512c5345de2ab8f698a687c6cec9973&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="2003658" author="xgen-internal-githook" created="Fri, 14 Sep 2018 20:08:42 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;David Storch&apos;, &apos;email&apos;: &apos;david.storch@10gen.com&apos;, &apos;username&apos;: &apos;dstorch&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-36993&quot; title=&quot;mongod crash:  Invariant failure indexedOr src/mongo/db/query/index_tag.cpp 237&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-36993&quot;&gt;&lt;del&gt;SERVER-36993&lt;/del&gt;&lt;/a&gt; Fix crash due to incorrect $or pushdown for indexed $expr.&lt;/p&gt;

&lt;p&gt;(cherry picked from commit ee97c0699fd55b498310996ee002328e533681a3)&lt;br/&gt;
Branch: v4.0&lt;br/&gt;
&lt;a href=&quot;https://github.com/mongodb/mongo/commit/0aebf209b1467df188b8915d507fc6a2dcf80ef8&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/mongodb/mongo/commit/0aebf209b1467df188b8915d507fc6a2dcf80ef8&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="2003231" author="xgen-internal-githook" created="Fri, 14 Sep 2018 16:06:44 +0000"  >&lt;p&gt;Author:&lt;/p&gt;
{&apos;name&apos;: &apos;David Storch&apos;, &apos;email&apos;: &apos;david.storch@10gen.com&apos;, &apos;username&apos;: &apos;dstorch&apos;}
&lt;p&gt;Message: &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-36993&quot; title=&quot;mongod crash:  Invariant failure indexedOr src/mongo/db/query/index_tag.cpp 237&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-36993&quot;&gt;&lt;del&gt;SERVER-36993&lt;/del&gt;&lt;/a&gt; Fix crash due to incorrect $or pushdown for indexed $expr.&lt;br/&gt;
Branch: master&lt;br/&gt;
&lt;a href=&quot;https://github.com/mongodb/mongo/commit/ee97c0699fd55b498310996ee002328e533681a3&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://github.com/mongodb/mongo/commit/ee97c0699fd55b498310996ee002328e533681a3&lt;/a&gt;&lt;/p&gt;</comment>
                            <comment id="1994232" author="david.storch" created="Wed, 5 Sep 2018 18:34:47 +0000"  >&lt;p&gt;This appears to be a bad interaction between $or pushdown from&#160;&lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-13732&quot; title=&quot;Predicates in top-level implicit AND query not considered when generating index access plan for contained OR&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-13732&quot;&gt;&lt;del&gt;SERVER-13732&lt;/del&gt;&lt;/a&gt; and the &lt;tt&gt;$expr&lt;/tt&gt;&#160;rewrite optimization implemented under &lt;a href=&quot;https://jira.mongodb.org/browse/SERVER-31760&quot; title=&quot;Lookup sub-pipeline is not using index for equality match&quot; class=&quot;issue-link&quot; data-issue-key=&quot;SERVER-31760&quot;&gt;&lt;del&gt;SERVER-31760&lt;/del&gt;&lt;/a&gt;. I&apos;m digging in a bit more in order to identify the proper fix.&lt;/p&gt;</comment>
                            <comment id="1993772" author="travis@bryx.com" created="Wed, 5 Sep 2018 14:35:33 +0000"  >&lt;p&gt;Thanks!  It also looks like you fixed my formatting, which I appreciate &lt;img class=&quot;emoticon&quot; src=&quot;https://jira.mongodb.org/images/icons/emoticons/smile.png&quot; height=&quot;16&quot; width=&quot;16&quot; align=&quot;absmiddle&quot; alt=&quot;&quot; border=&quot;0&quot;/&gt;&lt;/p&gt;</comment>
                            <comment id="1993751" author="thomas.schubert" created="Wed, 5 Sep 2018 14:26:56 +0000"  >&lt;p&gt;Thanks for report &lt;a href=&quot;https://jira.mongodb.org/secure/ViewProfile.jspa?name=travis%40bryx.com&quot; class=&quot;user-hover&quot; rel=&quot;travis@bryx.com&quot;&gt;travis@bryx.com&lt;/a&gt;, I&apos;ve reproed following your example and we&apos;re investigating.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10420">
                    <name>Backports</name>
                                            <outwardlinks description="backported by">
                                                        </outwardlinks>
                                                        </issuelinktype>
                            <issuelinktype id="10520">
                    <name>Problem/Incident</name>
                                            <outwardlinks description="causes">
                                                        </outwardlinks>
                                                        </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                <customfield id="customfield_10050" key="com.atlassian.jira.toolkit:comments">
                        <customfieldname># Replies</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>6.0</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_18555" key="com.onresolve.jira.groovy.groovyrunner:scripted-field">
                        <customfieldname># of Sprints</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1.0</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_12450" key="com.atlassian.jira.plugin.system.customfieldtypes:multicheckboxes">
                        <customfieldname>Backport Requested</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="15640"><![CDATA[v4.0]]></customfieldvalue>
    <customfieldvalue key="15141"><![CDATA[v3.6]]></customfieldvalue>
    
                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10011" key="com.atlassian.jira.plugin.system.customfieldtypes:radiobuttons">
                        <customfieldname>Backwards Compatibility</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10038"><![CDATA[Fully Compatible]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                            <customfield id="customfield_10055" key="com.atlassian.jira.ext.charting:firstresponsedate">
                        <customfieldname>Date of 1st Reply</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>Wed, 5 Sep 2018 14:26:56 +0000</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10052" key="com.atlassian.jira.toolkit:dayslastcommented">
                        <customfieldname>Days since reply</customfieldname>
                        <customfieldvalues>
                                        5 years, 21 weeks, 1 day ago
    
                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_18254" key="com.onresolve.jira.groovy.groovyrunner:scripted-field">
                        <customfieldname>Dependencies</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[]]></customfieldvalue>


                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_15850" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    <customfield id="customfield_10057" key="com.atlassian.jira.toolkit:lastusercommented">
                        <customfieldname>Last comment by Customer</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>true</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10056" key="com.atlassian.jira.toolkit:lastupdaterorcommenter">
                        <customfieldname>Last commenter</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>luke.bonanomi@mongodb.com</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_11151" key="com.atlassian.jira.toolkit:LastCommentDate">
                        <customfieldname>Last public comment date</customfieldname>
                        <customfieldvalues>
                            5 years, 21 weeks, 1 day ago
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                    <customfield id="customfield_10032" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Operating System</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10026"><![CDATA[ALL]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                <customfield id="customfield_10051" key="com.atlassian.jira.toolkit:participants">
                        <customfieldname>Participants</customfieldname>
                        <customfieldvalues>
                                        <customfieldvalue>david.storch@mongodb.com</customfieldvalue>
            <customfieldvalue>xgen-internal-githook</customfieldvalue>
            <customfieldvalue>kelsey.schubert@mongodb.com</customfieldvalue>
            <customfieldvalue>travis@bryx.com</customfieldvalue>
    
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                        <customfield id="customfield_14254" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Product Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hu75zj:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                <customfield id="customfield_12550" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>2|hr8qlb:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10558" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_23361" key="com.onresolve.jira.groovy.groovyrunner:scripted-field">
                        <customfieldname>Requested By</customfieldname>
                        <customfieldvalues>
                                

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                        <customfield id="customfield_10557" key="com.pyxis.greenhopper.jira:gh-sprint">
                        <customfieldname>Sprint</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue id="2467">Query 2018-09-24</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10053" key="com.atlassian.jira.ext.charting:timeinstatus">
                        <customfieldname>Time In Status</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_22870" key="com.onresolve.jira.groovy.groovyrunner:scripted-field">
                        <customfieldname>Triagers</customfieldname>
                        <customfieldvalues>
                                

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                    <customfield id="customfield_14350" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>serverRank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hu6s8v:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                    </customfields>
    </item>
</channel>
</rss>