vulnerability
MongoDB: Unspecified Security Vulnerability (CVE-2024-6384)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:N/AC:M/Au:S/C:C/I:N/A:N) | Aug 13, 2024 | Aug 19, 2024 | Jan 30, 2025 |
Severity
6
CVSS
(AV:N/AC:M/Au:S/C:C/I:N/A:N)
Published
Aug 13, 2024
Added
Aug 19, 2024
Modified
Jan 30, 2025
Description
"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise Server v7.3 versions prior to 7.3.3
Solution(s)
mongodb-upgrade-6_0_16mongodb-upgrade-7_0_11mongodb-upgrade-7_3_3

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.