MongoDb Missing Authorization Vulnerability - CVE-2024-6375 - Vulnerability Database

MongoDb Missing Authorization Vulnerability - CVE-2024-6375

Medium
Reference: CVE-2024-6375
Title: MongoDb Missing Authorization Vulnerability
Overview:

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard leading to either degradation of query performance or to revealing chunk boundaries through timing side channels. This affects MongoDB Server v5.0 versions prior to 5.0.22 MongoDB Server v6.0 versions prior to 6.0.11 and MongoDB Server v7.0 versions prior to 7.0.3.