CVE-2024-8654

MEDIUM

MongoDB Server <6.0.3 - Memory Corruption

Title source: llm
STIX 2.1

Description

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.

Scores

CVSS v3 5.0
EPSS 0.0045
EPSS Percentile 63.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-908
Status published
Products (1)
mongodb/mongodb 6.0.0 - 6.0.3
Published Sep 10, 2024
Tracked Since Feb 18, 2026