VDB

CVE-2024-3374

CVE-2024-3374 PUBLISHED

An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB Server v6.0 versions prior to and including 6.0.5.

EPSS 0.61% · 70.3th percentile

Risk Scores

EPSS Score
0.61%
70.3th percentile

Affected Products

VendorProductVersions
Bitnamimongodb5.0.0, 6.0.0
Bitnamimongodb5.0.0, 6.0.0

Exploit Intelligence

Timeline

  • May 14, 2024 CVE Published
  • May 15, 2024 EPSS Score
  • Jun 9, 2024 EPSS Score
  • Jul 3, 2024 EPSS Score
  • Aug 20, 2024 EPSS Score
  • Sep 12, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 6, 2024 EPSS Score
  • Oct 30, 2024 EPSS Score
  • Nov 23, 2024 EPSS Score
  • Dec 18, 2024 EPSS Score
  • Feb 4, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›