Vulnerability Details CVE-2024-8654
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.6%
CVSS Severity
CVSS v3 Score 5.0
Products affected by CVE-2024-8654
-
cpe:2.3:a:mongodb:mongodb:6.0.0
-
cpe:2.3:a:mongodb:mongodb:6.0.1
-
cpe:2.3:a:mongodb:mongodb:6.0.2
-
cpe:2.3:a:mongodb:mongodb:6.0.3