MongoDB Server (mongod) may crash when generating ftdc
Published May 14, 2024
5.3
MEDIUMCVSS 3.1
EPSS 0.46%
Description
An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB Server v6.0 versions prior to and including 6.0.5.
Affected products
-
Affected
- ≥ 5.0, ≤ 5.0.16
- ≥ 6.0, ≤ 6.0.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| MongoDB Inc | MongoDB Server | unaffected | Affected
|
No data.
Red Hat Openshift Container Storage 4
ocs4/mcg-core-rhel8
Out of support scope
Red Hat Openshift Data Foundation 4
noobaa-core-container
Not affected
Red Hat Openshift Data Foundation 4
odf4/mcg-core-rhel8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Openshift Container Storage 4 | ocs4/mcg-core-rhel8 | Out of support scope | n/a |
| Red Hat Openshift Data Foundation 4 | noobaa-core-container | Not affected | n/a |
| Red Hat Openshift Data Foundation 4 | odf4/mcg-core-rhel8 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2024-3374 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2280546 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31963 Advisory
- https://jira.mongodb.org/browse/SERVER-75601 Issue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-3374
- https://www.cve.org/CVERecord?id=CVE-2024-3374
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2024-3374 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2280546 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-31963 | Advisory | |
| https://jira.mongodb.org/browse/SERVER-75601 | Issue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-3374 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-3374 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data