CVE-2024-3371

MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*

History

06 Feb 2025, 17:58

Type Values Removed Values Added
References () https://jira.mongodb.org/browse/COMPASS-7260 - () https://jira.mongodb.org/browse/COMPASS-7260 - Vendor Advisory
First Time Mongodb
Mongodb compass
CWE NVD-CWE-Other
CPE cpe:2.3:a:mongodb:compass:*:*:*:*:*:*:*:*

Information

Published : 2024-04-24 17:15

Updated : 2025-02-06 17:58


NVD link : CVE-2024-3371

Mitre link : CVE-2024-3371

CVE.ORG link : CVE-2024-3371


JSON object : View

Products Affected

mongodb

  • compass
CWE
CWE-360

Trust of System Event Data

NVD-CWE-Other