CVE-2024-3371

MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*

History

06 Feb 2025, 17:58

Type Values Removed Values Added
First Time Mongodb
Mongodb compass
References () https://jira.mongodb.org/browse/COMPASS-7260 - () https://jira.mongodb.org/browse/COMPASS-7260 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CPE cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*
CWE NVD-CWE-Other

26 Apr 2024, 15:15

Type Values Removed Values Added
Summary MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.40.5. MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.

24 Apr 2024, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-24 17:15

Updated : 2025-02-06 17:58


NVD link : CVE-2024-3371

Mitre link : CVE-2024-3371


JSON object : View

Products Affected

mongodb

  • compass