VDB
CVE-2024-3372
CVE-2024-3372
PUBLISHED
Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.25.
EPSS 0.38% · 59.7th percentile
Risk Scores
EPSS Score
0.38%
59.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | mongodb | 5.0.0, 6.0.0, 7.0.0 |
| Bitnami | mongodb | 5.0.0, 6.0.0, 7.0.0 |
Timeline
- May 14, 2024 CVE Published
- May 15, 2024 EPSS Score
- Jun 9, 2024 EPSS Score
- Jul 3, 2024 EPSS Score
- Jul 27, 2024 EPSS Score
- Aug 1, 2024 CVE Updated
- Aug 20, 2024 EPSS Score
- Sep 12, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 6, 2024 EPSS Score
- Oct 30, 2024 EPSS Score
- Nov 23, 2024 EPSS Score