VDB
CVE-2024-3372
CVE-2024-3372
PUBLISHED
CVSS 7.5 HIGH
Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.25.
EPSS 0.55% · 44.2th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.55%
44.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | mongodb | 5.0.0, 6.0.0, 7.0.0 |
| Bitnami | mongodb | 5.0.0, 6.0.0, 7.0.0 |
Timeline
- May 14, 2024 CVE Published
- May 15, 2024 EPSS Score
- Jun 10, 2024 EPSS Score
- Jul 4, 2024 EPSS Score
- Jul 29, 2024 EPSS Score
- Aug 1, 2024 CVE Updated
- Aug 22, 2024 EPSS Score
- Sep 16, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 10, 2024 EPSS Score
- Nov 4, 2024 EPSS Score
- Nov 28, 2024 EPSS Score