VDB
CVE-2024-3374
CVE-2024-3374
PUBLISHED
CVSS 5.300000190734863 MEDIUM
An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB Server v6.0 versions prior to and including 6.0.5.
EPSS 0.46% · 37.3th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.46%
37.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | mongodb | 5.0.0, 6.0.0 |
| Bitnami | mongodb | 5.0.0, 6.0.0 |
Timeline
- May 14, 2024 CVE Published
- May 15, 2024 EPSS Score
- Jun 9, 2024 EPSS Score
- Jul 4, 2024 EPSS Score
- Aug 1, 2024 CVE Updated
- Aug 21, 2024 EPSS Score
- Sep 15, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 9, 2024 EPSS Score
- Nov 2, 2024 EPSS Score
- Nov 27, 2024 EPSS Score
- Dec 22, 2024 EPSS Score