SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-6384

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier.

MEDIUM 5.3EPSS 0.43%

Does this matter?

Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.

Description

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise Server v7.3 versions prior to 7.3.3

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.43% probability · 36th percentile
CISA KEV
Not listed
Weakness
CWE-285
Affected
mongodb/mongodb
Source
cna@mongodb.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.