CVE Vulnerabilities

CVE-2024-8654

Use of Uninitialized Resource

Published: Sep 10, 2024 | Modified: Sep 22, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

NameVendorStart VersionEnd Version
MongodbMongodb6.0.0 (including)6.0.3 (including)
MongodbUbuntufocal*
MongodbUbuntutrusty/esm*
MongodbUbuntuupstream*

Potential Mitigations

References