VYPR
Low severity2.2NVD Advisory· Published Oct 28, 2024· Updated Jun 17, 2026

CVE-2024-8013

CVE-2024-8013

Description

A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue affects mongocryptd binary (v5.0 versions prior to 5.0.29, v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) and mongo_crypt_v1.so shared libraries (v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) released alongside MongoDB Enterprise Server versions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • MongoDB/mongo_crypt_v1.sollm-create2 versions
    <6.0.17, <7.0.12, <7.3.4+ 1 more
    • (no CPE)range: <6.0.17, <7.0.12, <7.3.4
    • cpe:2.3:a:mongodb:mongo_crypt_v1.so:*:*:*:*:*:mongodb:*:*range: >=6.0.0,<6.0.17
  • MongoDB/mongocryptdllm-create2 versions
    <5.0.29, <6.0.17, <7.0.12, <7.3.4+ 1 more
    • (no CPE)range: <5.0.29, <6.0.17, <7.0.12, <7.3.4
    • cpe:2.3:a:mongodb:mongocryptd:*:*:*:*:*:mongodb:*:*range: >=5.0.0,<5.0.29
  • MongoDB Inc/mongocryptdv5
    cpe:2.3:a:mongodb:mongo_crypt_v1.so:6.0.0:*:*:*:*:mongodb:*:*
    Range: 5.0
  • MongoDB Inc/Mongo_crypt_v1.sov5
    Range: 6.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.