← Back

CVE-2024-6384

nvd nist
Published: Aug 13, 2024Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.6 / Impact: 3.6
Source: NVD

Description

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise Server v7.3 versions prior to 7.3.3

Affected (3)

Products: Mongodb: Mongodb
1 product
Mongodb
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mongodb
From 6.0.0 to 6.0.16
From 7.0.0 to 7.0.11
From 7.3.0 to 7.3.3

References (2)

Source: cna@mongodb.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.