CVE-2024-3371
HIGHDescription
MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.
Is your site exposed to CVE-2024-3371?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mongodb | compass |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-3371? +
How severe is CVE-2024-3371? +
What products are affected by CVE-2024-3371? +
How do I check if I'm vulnerable to CVE-2024-3371? +
Related Vulnerabilities
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally …
Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections …
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds …
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database …
The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that …
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause …