First published: Tue Sep 10 2024(Updated: )
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.
Credit: cna@mongodb.com
Affected Software | Affected Version | How to fix |
---|---|---|
MongoDB |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8654 has been rated as having a moderate severity level due to potential unexpected behavior.
To fix CVE-2024-8654, update your MongoDB Server to version 6.0.4 or later.
CVE-2024-8654 affects MongoDB Server version 6.0.3.
CVE-2024-8654 may lead to unexpected behavior when zero arguments are called in an internal aggregation stage.
No specific workaround for CVE-2024-8654 is provided; upgrading to the fixed version is recommended.