CyberRota Analysis
AI-GeneratedMongoDB Connector for BI instances are vulnerable to a denial-of-service attack, where an unauthenticated attacker can generate excessive connection log activity, leading to storage exhaustion. This results in the mongosqld process crashing and becoming unavailable for all connected SQL clients until storage is restored, with no diagnostic message logged to aid in troubleshooting. Organizations using MongoDB should prioritize addressing this vulnerability to prevent potential service disruptions.
Original NVD Description
An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operation subsequently fails, the resulting error is not handled and the shared mongosqld process ends, ending service for all connected SQL clients. The process continues to end on startup until an operator restores available storage, and the diagnostic message explaining the condition is not recorded.