Description
An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.
Remediation
References
Related Vulnerabilities
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-9041)
Drupal Core 4.5.x Cross-Site Scripting (4.5.0 - 4.5.5)
Oracle Database Server CVE-2018-2875 Vulnerability (CVE-2018-2875)
WordPress Plugin Social Share Icons & Social Share Buttons Unspecified Vulnerability (1.4)
Jenkins Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3663)