Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-6375


A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server v5.0 versions, prior to 5.0.22, MongoDB Server v6.0 versions, prior to 6.0.11 and MongoDB Server v7.0 versions prior to 7.0.3.


Published

2024-07-01T15:15:17.430

Last Modified

2024-11-21T09:49:31.330

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-285
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mongodb mongodb < 5.0.22 Yes
Application mongodb mongodb < 6.0.11 Yes
Application mongodb mongodb < 7.0.3 Yes

References