BIT-mongodb-2024-6384

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mongodb/BIT-mongodb-2024-6384.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-mongodb-2024-6384
Aliases
Published
2024-08-17T07:25:17.062Z
Modified
2024-11-27T19:40:48.342Z
Summary
[none]
Details

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise Server v7.3 versions prior to 7.3.3

Database specific
{
    "cpes": [
        "cpe:2.3:a:mongodb:mongodb:*:*:*:*:enterprise:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / mongodb

Package

Name
mongodb
Purl
pkg:bitnami/mongodb

Severity

  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
6.0.0
Fixed
6.0.16
Introduced
7.0.0
Fixed
7.0.11
Introduced
7.3.0
Fixed
7.3.3