Security readout for executives and security teams
Plain-English summary
CVE-2020-7923 is a MongoDB Server denial-of-service flaw. An authenticated user who can run database queries could send specially crafted geoNear-related queries that disrupt the server by violating an internal query invariant. The stated impact is availability only, with no confidentiality or integrity impact in the CVSS data.
Executive priority
Treat as a moderate-priority availability risk. It should be remediated during normal patch cycles, faster for internet-accessible, multi-tenant, or externally integrated database environments where lower-privileged accounts have query access.
Technical view
The issue affects MongoDB Server 4.4 before 4.4.0-rc7, 4.2 before 4.2.8, and 4.0 before 4.0.19. It is classified under CWE-755 and has CVSS 3.1 score 6.5: network reachable, low complexity, low privileges required, no user interaction, and high availability impact.
Likely exposure
Exposure is most likely where affected MongoDB Server versions allow authenticated users or application accounts to perform database queries involving geospatial query functionality. Systems already upgraded beyond the listed fixed versions are not indicated as affected by the source bundle.
Exploitation context
The source bundle does not show CISA KEV listing or cited active exploitation. Exploitation requires query privileges, so this is not described as unauthenticated remote compromise. The business risk is service interruption if a permitted database user or compromised account can issue crafted queries.
Researcher notes
The provided evidence identifies the vulnerability class, affected version ranges, privilege requirement, and availability impact, but does not include exploit details or broad exploitation evidence. Validation should focus on version exposure and account capability, not reproducing crafted queries in production.
Mitigation direction
- Upgrade MongoDB Server 4.0 to 4.0.19 or later.
- Upgrade MongoDB Server 4.2 to 4.2.8 or later.
- Avoid affected MongoDB Server 4.4 builds before 4.4.0-rc7.
- Review MongoDB vendor guidance for any deployment-specific recommendations.
- Limit query privileges to accounts that need database access.
Validation and detection
- Inventory MongoDB Server versions across production and non-production systems.
- Confirm no 4.0 deployments are below 4.0.19.
- Confirm no 4.2 deployments are below 4.2.8.
- Confirm any 4.4 pre-release deployments are at least 4.4.0-rc7.
- Review database account permissions for unnecessary query access.
- Check availability incidents against MongoDB logs without reproducing the issue.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-755: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupDatabase behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2020-7923 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H2.83.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.5MediumVector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://jira.mongodb.org/browse/SERVER-47773CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Improper Handling of Exceptional Conditions
Improper Handling of Exceptional Conditions represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
