CVE-2024-3372

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.25.
References
Link Resource
https://jira.mongodb.org/browse/SERVER-85263 Issue Tracking Vendor Advisory
https://jira.mongodb.org/browse/SERVER-85263 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*

History

22 Sep 2025, 13:36

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/SERVER-85263 - () https://jira.mongodb.org/browse/SERVER-85263 - Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
First Time Mongodb mongodb
Mongodb

21 Nov 2024, 09:29

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/SERVER-85263 - () https://jira.mongodb.org/browse/SERVER-85263 -

14 May 2024, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:17

Updated : 2025-09-22 13:36


NVD link : CVE-2024-3372

Mitre link : CVE-2024-3372

CVE.ORG link : CVE-2024-3372


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
CWE-20

Improper Input Validation