CVE Vulnerabilities

CVE-2024-6382

Improper Handling of Syntactically Invalid Structure

Published: Jul 02, 2024 | Modified: Oct 02, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. This issue affects MongoDB Rust Driver 2.0 versions prior to 2.8.2

Weakness

The product does not handle or incorrectly handles input that is not syntactically well-formed with respect to the associated specification.

Affected Software

Name Vendor Start Version End Version
Rust_driver Mongodb 2.0.0 (including) 2.8.2 (excluding)

References