Executive brief
The MongoDB Node.js driver (npm package) fails to properly handle exceptions when working with invalid collection names on non-existent databases, causing application crashes. An attacker or misconfigured client can trigger this flaw to disrupt service availability by forcing the application to terminate unexpectedly.
Technical details
The vulnerability is an unhandled exception flaw in the MongoDB Node.js driver (npm package). When a collection name is invalid and the database does not exist, the driver fails to catch an exception, leading to an application crash. The attack vector is local or network-based depending on how the driver is exposed; an attacker or malicious client can send requests with invalid collection names to trigger the denial of service. No authentication bypass or data access is possible; the impact is limited to application availability. The flaw affects all versions prior to 3.1.13, which introduced proper exception handling. A patch is available by upgrading to version 3.1.13 or later.
Affected products
- MongoDB Node.js Driver before 3.1.13
Timeline
- 2020-09-03: disclosed
- 2020-09-03: patched: Fix available in version 3.1.13 and later