CVE-2024-8305

prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause multiple secondaries crashing leading to no primaries. This issue affects MongoDB Server v6.0 versions prior to 6.0.17, MongoDB Server v7.0 versions prior to 7.0.13 and MongoDB Server v7.3 versions prior to 7.3.4
References
Link Resource
https://jira.mongodb.org/browse/SERVER-92382 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*

History

07 Nov 2024, 15:38

Type Values Removed Values Added
First Time Mongodb mongodb
Mongodb
CPE cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
CWE NVD-CWE-Other
References () https://jira.mongodb.org/browse/SERVER-92382 - () https://jira.mongodb.org/browse/SERVER-92382 - Vendor Advisory
Summary
  • (es) El índice prepareUnique puede provocar que los secundarios se bloqueen debido a la aplicación incorrecta de restricciones de índice en los secundarios, lo que en casos extremos puede provocar que varios secundarios se bloqueen y no haya primarios. Este problema afecta a las versiones de MongoDB Server v6.0 anteriores a la 6.0.17, a las versiones de MongoDB Server v7.0 anteriores a la 7.0.13 y a las versiones de MongoDB Server v7.3 anteriores a la 7.3.4.

21 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-21 15:15

Updated : 2024-11-07 15:38


NVD link : CVE-2024-8305

Mitre link : CVE-2024-8305

CVE.ORG link : CVE-2024-8305


JSON object : View

Products Affected

mongodb

  • mongodb
CWE
NVD-CWE-Other CWE-1288

Improper Validation of Consistency within Input