First published: Mon Oct 21 2024(Updated: )
prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause multiple secondaries crashing leading to no primaries. This issue affects MongoDB Server v6.0 versions prior to 6.0.17, MongoDB Server v7.0 versions prior to 7.0.13 and MongoDB Server v7.3 versions prior to 7.3.4
Credit: cna@mongodb.com
Affected Software | Affected Version | How to fix |
---|---|---|
MongoDB | >=6.0.0<6.0.17 | |
MongoDB | >=7.0.0<7.0.13 | |
MongoDB | >=7.3.0<7.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-8305 is high due to the potential for multiple secondary nodes to crash.
To fix CVE-2024-8305, upgrade your MongoDB Server to version 6.0.17 or later, or to version 7.0.13 or later.
CVE-2024-8305 affects MongoDB Server versions 6.0.0 to 6.0.16, 7.0.0 to 7.0.12, and 7.3.0 to 7.3.3.
The potential impact of CVE-2024-8305 includes crashing secondary nodes, which may lead to a loss of primary functionality.
There are no known workarounds for CVE-2024-8305, so it is essential to upgrade to a fixed version.