CVE-2024-6375

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server v5.0 versions, prior to 5.0.22, MongoDB Server v6.0 versions, prior to 6.0.11 and MongoDB Server v7.0 versions prior to 7.0.3.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-79327 Issue Tracking Patch Vendor Advisory
https://jira.mongodb.org/browse/SERVER-79327 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 5.4
References () https://jira.mongodb.org/browse/SERVER-79327 - Issue Tracking, Patch, Vendor Advisory () https://jira.mongodb.org/browse/SERVER-79327 - Issue Tracking, Patch, Vendor Advisory

03 Jul 2024, 14:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
References () https://jira.mongodb.org/browse/SERVER-79327 - () https://jira.mongodb.org/browse/SERVER-79327 - Issue Tracking, Patch, Vendor Advisory
CWE CWE-862
First Time Mongodb mongodb
Mongodb
Summary
  • (es) A un comando para refinar una clave de fragmento de colección le falta una verificación de autorización. Esto puede hacer que el comando se ejecute directamente en un fragmento, lo que provoca una degradación del rendimiento de la consulta o revela límites de fragmentos a través de canales laterales de temporización. Esto afecta a las versiones de MongoDB Server v5.0, anteriores a la 5.0.22, a las versiones de MongoDB Server v6.0, anteriores a la 6.0.11 y a las versiones de MongoDB Server v7.0 anteriores a la 7.0.3.

01 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-01 15:15

Updated : 2024-11-21 09:49


NVD link : CVE-2024-6375

Mitre link : CVE-2024-6375

CVE.ORG link : CVE-2024-6375


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-285

Improper Authorization

CWE-862

Missing Authorization