CVE-2024-6376
Last modified
CVE-2024-6376 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | Compass | < 1.42.2 |
References
- https://jira.mongodb.org/browse/COMPASS-7496Issue Tracking, Patch, Vendor Advisory
- https://jira.mongodb.org/browse/COMPASS-7496Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-6376?
How severe is CVE-2024-6376?
How do I fix CVE-2024-6376?
Are you affected by CVE-2024-6376?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
