Record summary

CVE-2024-6376 has a selected CVSS score of 7.0 (high).

Description

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 1, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 1.42.2affected

@mongodb-js/connection-form

Browse npm / @mongodb-js/connection-form
GitHub AdvisoryBefore 1.20.1 · Fixed in 1.20.1affected

References

4