MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://jira.mongodb.org/browse/COMPASS-7496 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mongodb
Published: 2024-07-01T14:57:31.704Z
Updated: 2024-08-01T21:33:05.431Z
Reserved: 2024-06-27T07:55:22.098Z
Link: CVE-2024-6376
Vulnrichment
Updated: 2024-08-01T21:33:05.431Z
NVD
Status : Modified
Published: 2024-07-01T15:15:17.673
Modified: 2024-11-21T09:49:31.510
Link: CVE-2024-6376
Redhat
No data.