CVE-2024-6375 Information
Jul 02, 2024
cve
Description
A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard leading to either degradation of query performance or to revealing chunk boundaries through timing side channels. This affects MongoDB Server v5.0 versions prior to 5.0.22 MongoDB Server v6.0 versions prior to 6.0.11 and MongoDB Server v7.0 versions prior to 7.0.3.
Reference
https://jira.mongodb.org/browse/SERVER-79327
Share on: