VYPR
Medium severity5.0NVD Advisory· Published Sep 10, 2024· Updated Jun 17, 2026

CVE-2024-8654

CVE-2024-8654

Description

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB Server v6.0 version 6.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • MongoDB/MongoDB2 versions
    cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*range: >=6.0.0,<=6.0.3
    • cpe:2.3:a:mongodb:mongodb:6.0.3:*:*:*:*:*:*:*range: 6.0.3
  • MongoDB/Serverllm-fuzzy
    Range: =6.0.3
  • osv-coords
    Range: >= 6.0.0, < 6.0.15

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.