CVE Vulnerabilities

CVE-2024-8654

Use of Uninitialized Resource

Published: Sep 10, 2024 | Modified: Sep 22, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.

Weakness

The product uses or accesses a resource that has not been initialized.

Affected Software

Name Vendor Start Version End Version
Mongodb Mongodb 6.0.0 (including) 6.0.3 (including)
Mongodb Ubuntu focal *
Mongodb Ubuntu trusty/esm *

Potential Mitigations

References