CVE-2024-3371
HIGHDescription
MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.
Is your site exposed to CVE-2024-3371?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mongodb | compass |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-3371? +
How severe is CVE-2024-3371? +
What products are affected by CVE-2024-3371? +
How do I check if I'm vulnerable to CVE-2024-3371? +
Related Vulnerabilities
Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections …
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds …
The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that …
A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check …
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to …
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling …