PT-2024-6361 · Mongodb+1 · Mongodb Enterprise Server+2

Karman Liu

·

Published

2024-08-13

·

Updated

2025-01-13

·

CVE-2024-6384

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MongoDB Enterprise Server versions prior to 6.0.16 MongoDB Enterprise Server versions prior to 7.0.11 MongoDB Enterprise Server versions prior to 7.3.3
Description Underprivileged users may download "hot" backup files if they can acquire a unique backup identifier. This issue allows unauthorized access to sensitive data.
Recommendations For MongoDB Enterprise Server versions prior to 6.0.16, update to version 6.0.16 or later. For MongoDB Enterprise Server versions prior to 7.0.11, update to version 7.0.11 or later. For MongoDB Enterprise Server versions prior to 7.3.3, update to version 7.3.3 or later.

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11726
BDU:2024-07400
BIT-MONGODB-2024-6384
CVE-2024-6384

Affected Products

Alt Linux
Mongodb Enterprise Server
Mongodb