CVE-2024-3371CWE-360

Insufficient validation of external input in Compass may enable MITM attacks

High · published April 24, 2024

CVSS v3.1
7.1
EPSS
0%
Percentile
13.9
In the wild
Unconfirmed
What it is

MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.

The record
Technical detail
CVSS v3.1
7.1 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
CVSS v4.0
Not supplied
EPSS
0.00231 · 13.9th percentile
Weakness
CWE-360 · Trust of System Event Data
Published
2024-04-24T16:32Z
EPSS history
Timeline
  • 24 APR 16:32Z
    Insufficient validation of external input in Compass may enable MITM attacks
    cvelistv5