CVE-2024-8654: MongoDB Server may access non-initialized region of memory leading to unexpected behaviour
Published Sep 10, 2024
·Updated
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.
Affected Software
2 affected components
MongoDB Server
MongoDB MongoDB>=6.0.0<=6.0.3
Event History
Sep 10, 2024
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-8654?
CVE-2024-8654 has been rated as having a moderate severity level due to potential unexpected behavior.
2
How do I fix CVE-2024-8654?
To fix CVE-2024-8654, update your MongoDB Server to version 6.0.4 or later.
3
What versions of MongoDB Server are affected by CVE-2024-8654?
CVE-2024-8654 affects MongoDB Server version 6.0.3.
4
What impact does CVE-2024-8654 have on MongoDB Server?
CVE-2024-8654 may lead to unexpected behavior when zero arguments are called in an internal aggregation stage.
5
Is there a workaround for CVE-2024-8654?
No specific workaround for CVE-2024-8654 is provided; upgrading to the fixed version is recommended.