MongoDB Server may have unexpected application behaviour due to invalid BSON
Published May 14, 2024
7.5
HIGHCVSS 3.1
EPSS 0.55%
Description
Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.25.
Affected products
-
- Version 5.0StatusaffectedConstraints<5.0.25
- Version 6.0StatusaffectedConstraints<6.0.14
- Version 7.0StatusaffectedConstraints<7.0.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| MongoDB Inc | MongoDB Server | unaffected |
|
No data.
Red Hat Openshift Container Storage 4
ocs4/mcg-core-rhel8
Out of support scope
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Openshift Container Storage 4 | ocs4/mcg-core-rhel8 | Out of support scope | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel8 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2024-3372 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2280683 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31961 Advisory
- https://jira.mongodb.org/browse/SERVER-85263 Issue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-3372
- https://www.cve.org/CVERecord?id=CVE-2024-3372
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-3372 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2280683 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31961 | Advisory | |
| https://jira.mongodb.org/browse/SERVER-85263 | Issue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-3372 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-3372 |
Change history (0)
No recorded changes yet.