PT-2024-39153 · Mongodb+1 · Mongodb Server+2

Pol Pinol Castuera

+1

·

Published

2024-09-10

·

Updated

2025-09-23

·

CVE-2024-8654

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: MongoDB Server version 6.0.3
Description: The issue is related to MongoDB Server accessing a non-initialized region of memory, leading to unexpected behavior when zero arguments are called in an internal aggregation stage.
Recommendations: For MongoDB Server version 6.0.3, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

ALT-PU-2024-12981
ALT-PU-2024-13160
ALT-PU-2024-13256
BIT-MONGODB-2024-8654
CVE-2024-8654

Affected Products

Alt Linux
Mongodb Server
Mongodb