github.com
https://github.com/mongodb-js/compass CVE-2024-6376
HIGH
ejson shell parser in MongoDB Compass maybe bypassed
Record summary
CVE-2024-6376 has a selected CVSS score of 7.0 (high).
Description
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 1, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
MongoDB CompassBrowse MongoDB Inc / MongoDB CompassDefault status: unaffected | CVE List | Before 1.42.2 | affected |
@mongodb-js/connection-formBrowse npm / @mongodb-js/connection-form | GitHub Advisory | Before 1.20.1 · Fixed in 1.20.1 | affected |
References
4github.com
https://github.com/mongodb-js/compass/commit/b1f8050d49d66be3bc499cb317a1e1de45390e51 jira.mongodb.org
https://jira.mongodb.org/browse/COMPASS-7496 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6376