Description
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify memory.
Remediation
References
Related Vulnerabilities
Jenkins Use of Insufficiently Random Values Vulnerability (CVE-2020-2099)
MySQL CVE-2015-0500 Vulnerability (CVE-2015-0500)
WordPress Plugin Software License Manager Cross-Site Request Forgery (4.4.5)
Grafana Cleartext Storage of Sensitive Information Vulnerability (CVE-2022-26148)
WordPress Plugin File Manager Pro Arbitrary File Upload (8.3.4)