CVE-2024-6375

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server v5.0 versions, prior to 5.0.22, MongoDB Server v6.0 versions, prior to 6.0.11 and MongoDB Server v7.0 versions prior to 7.0.3.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-79327 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-07-01 15:15

Updated : 2024-07-03 14:54


NVD link : CVE-2024-6375

Mitre link : CVE-2024-6375

CVE.ORG link : CVE-2024-6375


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-862

Missing Authorization

CWE-285

Improper Authorization