CVE-2024-6382

Published Jul 2, 2024

Last updated 10 months ago

CVSS medium 6.4
MongoDB
Rust

Overview

AI description

Automated description summarized from trusted sources.

CVE-2024-6382 is a vulnerability affecting the MongoDB Rust Driver. Specifically, versions 2.0 prior to 2.8.2 are affected. The vulnerability stems from the incorrect handling of certain string inputs, which can lead the driver to construct unintended server commands. This mishandling of string inputs may result in unexpected application behavior. The vulnerability can be exploited over a network connection and requires minimal skill to exploit. To mitigate this vulnerability, it is recommended to upgrade to version 2.8.2 or later of the MongoDB Rust Driver.

Description
Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2
Source
cna@mongodb.com
NVD status
Analyzed
Products
rust_driver

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity
HIGH

Weaknesses

cna@mongodb.com
CWE-228

Social media

Hype score
Not currently trending

Configurations