CVE-2024-3374: MongoDB Server (mongod) may crash when generating ftdc
An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB Server v6.0 versions prior to and including 6.0.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3374?
CVE-2024-3374 has a high severity due to its ability to cause a fatal assertion in the server.
How do I fix CVE-2024-3374?
To fix CVE-2024-3374, upgrade to MongoDB Server version 5.0.17 or higher, or version 6.0.6 or higher.
Which versions of MongoDB are affected by CVE-2024-3374?
CVE-2024-3374 affects MongoDB Server versions up to and including 5.0.16 and up to and including 6.0.5.
What are the potential impacts of CVE-2024-3374?
The potential impacts of CVE-2024-3374 include service disruption due to fatal assertions when generating diagnostic metrics.
Is it possible to exploit CVE-2024-3374 without authentication?
Yes, CVE-2024-3374 can be exploited by unauthenticated users, allowing them to trigger server failures.