First published: Tue May 14 2024(Updated: )
An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB Server v6.0 versions prior to and including 6.0.5.
Credit: cna@mongodb.com
Affected Software | Affected Version | How to fix |
---|---|---|
MongoDB Server | <=5.0.16 | |
MongoDB Server | <=6.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3374 has a high severity due to its ability to cause a fatal assertion in the server.
To fix CVE-2024-3374, upgrade to MongoDB Server version 5.0.17 or higher, or version 6.0.6 or higher.
CVE-2024-3374 affects MongoDB Server versions up to and including 5.0.16 and up to and including 6.0.5.
The potential impacts of CVE-2024-3374 include service disruption due to fatal assertions when generating diagnostic metrics.
Yes, CVE-2024-3374 can be exploited by unauthenticated users, allowing them to trigger server failures.