CVE-2021-20330
Estado: ModificadaMedia (6.5)—
An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.05%
- Percentil entre todas las CVEs puntuadas: 63
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-20330",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2021-20330",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-01-23T21:25:43.265292Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"authentication": "SINGLE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@mongodb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cna@mongodb.com",
"affectedData": [
{
"vendor": "MongoDB Inc.",
"product": "MongoDB Server",
"versions": [
{
"status": "affected",
"version": "4.0",
"lessThan": "4.0.27",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.2",
"lessThan": "4.2.16",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.4",
"lessThan": "4.4.9",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*"
],
"vendor": "mongodb",
"product": "mongodb",
"versions": [
{
"status": "affected",
"version": "4.0",
"lessThan": "4.0.27",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.2",
"lessThan": "4.2.18",
"versionType": "custom"
},
{
"status": "affected",
"version": "4.4",
"lessThan": "4.4.9",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2021-12-15T13:15:07.633",
"references": [
{
"url": "https://jira.mongodb.org/browse/SERVER-36263",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "cna@mongodb.com"
},
{
"url": "https://jira.mongodb.org/browse/SERVER-36263",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@mongodb.com",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9."
},
{
"lang": "es",
"value": "Un atacante con permisos CRUD básicos en una colección replicada puede ejecutar el comando applyOps con entradas oplog especialmente malformadas, resultando en una potencial denegación de servicio en los secundarios. Este problema afecta a las versiones de MongoDB Server v4.0 anteriores a 4.0.25; a las versiones de MongoDB Server v4.2 anteriores a 4.2.14; a las versiones de MongoDB Server v4.4 anteriores a 4.4.6"
}
],
"lastModified": "2026-06-17T03:33:41.200",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50CB3881-049A-46F5-BBB4-21DCF2466D49",
"versionEndExcluding": "4.0.25",
"versionStartIncluding": "4.0.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66EE5895-9252-49DE-810E-586E1AC484ED",
"versionEndExcluding": "4.2.14",
"versionStartIncluding": "4.2.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "177D5982-E1C3-42F0-B2E8-3345EB8C22F2",
"versionEndExcluding": "4.4.6",
"versionStartIncluding": "4.4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@mongodb.com"
}