Show plain JSON{"id": "CVE-2024-6384", "metrics": {"cvssMetricV31": [{"type": "Secondary", "source": "cna@mongodb.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 1.6}, {"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 1.6}]}, "published": "2024-08-13T15:15:18.567", "references": [{"url": "https://jira.mongodb.org/browse/SERVER-93516", "tags": ["Vendor Advisory"], "source": "cna@mongodb.com"}, {"url": "https://security.netapp.com/advisory/ntap-20241115-0001/", "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "cna@mongodb.com", "description": [{"lang": "en", "value": "CWE-285"}]}, {"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "\"Hot\" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise Server v7.3 versions prior to 7.3.3"}, {"lang": "es", "value": "Los usuarios desfavorecidos pueden descargar archivos de copia de seguridad \"calientes\", si son capaces de adquirir un identificador de copia de seguridad \u00fanico. Este problema afecta a las versiones de MongoDB Enterprise Server v6.0 anteriores a 6.0.16, a las versiones de MongoDB Enterprise Server v7.0 anteriores a 7.0.11 y a las versiones de MongoDB Enterprise Server v7.3 anteriores a 7.3.3."}], "lastModified": "2024-11-21T09:49:32.613", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "97040FB6-7E95-4407-998C-BBB4D80654AD", "versionEndExcluding": "6.0.16", "versionStartIncluding": "6.0.0"}, {"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "CCCE67E2-B4AD-4375-9045-4A702B1D1056", "versionEndExcluding": "7.0.11", "versionStartIncluding": "7.0.0"}, {"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "ACB90095-374D-427A-899E-1607155BB924", "versionEndExcluding": "7.3.3", "versionStartIncluding": "7.3.0"}], "operator": "OR"}]}], "sourceIdentifier": "cna@mongodb.com"}