Sploitus

CVE-2024-6375

No indexed exploits for CVE-2024-6375 yet

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels. This affects MongoDB Server v5.0 versions, prior to 5.0.22, MongoDB Server v6.0 versions, prior to 6.0.11 and MongoDB Server v7.0 versions prior to 7.0.3.

Mongodb
< 5.0.22, 6.0.11, 7.0.3
Fix
Available
CVSS 3.1
6.5 MEDIUM
EPSS
0.4% (30th percentile)
Weakness
CWE-285, CWE-862
NVD status
Modified
Published
2024-07-01
CVE-2024-6375 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-6375 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-6375 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.