icon

We found results for “

CVE-2024-3371

Good to know:

icon
icon
icon

Date: April 24, 2024

MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.

Language: TYPE_SCRIPT

Severity Score

Severity Score

Weakness Type (CWE)

Trust of System Event Data

CWE-360

Top Fix

icon

Upgrade Version

Upgrade to version compass-preferences-model - 2.18.1, mongodb-js/compass - v1.42.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us