CVE Feed

    Dashboard / CVE / CVE-2024-8207

    CVE-2024-8207

    In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cause the MongoDB Server binary to load unintended actor-controlled shared libraries when the server binary is started, potentially resulting in the unintended actor gaining full control over the MongoDB server process. This issue affects MongoDB Server v5.0 versions prior to 5.0.14 and MongoDB Server v6.0 versions prior to 6.0.3. Required Configuration: Only environments with Linux as the underlying operating system is affected by this issue

    Published:Aug 27, 2024
    Last Modified:May 16, 2025
    EPS:Aug 27, 2024
    EPSS Score:0.00025
    CVSS Score:6.4

    Affected Products

    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Mongodb
    Product
    Mongodb

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High