VDB

CVE-2024-3372

CVE-2024-3372 PUBLISHED CVSS 7.5 HIGH

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.25.

EPSS 0.55% · 44.2th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.55%
44.2th percentile

Affected Products

VendorProductVersions
Bitnamimongodb5.0.0, 6.0.0, 7.0.0
Bitnamimongodb5.0.0, 6.0.0, 7.0.0

Timeline

  • May 14, 2024 CVE Published
  • May 15, 2024 EPSS Score
  • Jun 10, 2024 EPSS Score
  • Jul 4, 2024 EPSS Score
  • Jul 29, 2024 EPSS Score
  • Aug 1, 2024 CVE Updated
  • Aug 22, 2024 EPSS Score
  • Sep 16, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 10, 2024 EPSS Score
  • Nov 4, 2024 EPSS Score
  • Nov 28, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›