CVE-2024-6375

MEDIUM

MongoDB <5.0.22-6.0.11-7.0.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server v5.0 versions, prior to 5.0.22, MongoDB Server v6.0 versions, prior to 6.0.11 and MongoDB Server v7.0 versions prior to 7.0.3.

References (1)

Core 1
Core References
Issue Tracking, Patch, Vendor Advisory
https://jira.mongodb.org/browse/SERVER-79327

Scores

CVSS v3 5.4
EPSS 0.0038
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-862
Status published
Products (1)
mongodb/mongodb 5.0.0 - 5.0.22
Published Jul 01, 2024
Tracked Since Feb 18, 2026