CVE-2024-6384
Status: ModifiedMedium (5.3)—
"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise Server v7.3 versions prior to 7.3.3
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- Base score: 5.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.43%
- Percentile among all scored CVEs: 35
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-285
- NVD-CWE-noinfo
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-6384",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-6384",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-08-13T16:05:08.483694Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@mongodb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.6
}
]
},
"affected": [
{
"source": "cna@mongodb.com",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:mongodb:mongodb:6.0.0:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.1:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.2:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.3:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.4:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.5:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.6:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.7:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.8:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.9:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.10:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.11:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.12:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.13:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.14:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:6.0.15:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.0:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.1:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.2:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.3:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.4:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.5:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.6:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.7:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.8:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.0.9:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.3.1:*:*:*:enterprise:*:*:*",
"cpe:2.3:a:mongodb:mongodb:7.3.2:*:*:*:enterprise:*:*:*"
],
"vendor": "MongoDB Inc",
"product": "MongoDB Server",
"versions": [
{
"status": "affected",
"version": "6.0",
"lessThan": "6.0.16",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.0",
"lessThan": "7.0.11",
"versionType": "custom"
},
{
"status": "affected",
"version": "7.3",
"lessThan": "7.3.3",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-08-13T15:15:18.567",
"references": [
{
"url": "https://jira.mongodb.org/browse/SERVER-93516",
"tags": [
"Vendor Advisory"
],
"source": "cna@mongodb.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20241115-0001/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@mongodb.com",
"description": [
{
"lang": "en",
"value": "CWE-285"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "\"Hot\" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versions prior to 6.0.16, MongoDB Enterprise Server v7.0 versions prior to 7.0.11 and MongoDB Enterprise Server v7.3 versions prior to 7.3.3"
},
{
"lang": "es",
"value": "Los usuarios desfavorecidos pueden descargar archivos de copia de seguridad \"calientes\", si son capaces de adquirir un identificador de copia de seguridad único. Este problema afecta a las versiones de MongoDB Enterprise Server v6.0 anteriores a 6.0.16, a las versiones de MongoDB Enterprise Server v7.0 anteriores a 7.0.11 y a las versiones de MongoDB Enterprise Server v7.3 anteriores a 7.3.3."
}
],
"lastModified": "2026-06-17T08:17:54.320",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97040FB6-7E95-4407-998C-BBB4D80654AD",
"versionEndExcluding": "6.0.16",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CCCE67E2-B4AD-4375-9045-4A702B1D1056",
"versionEndExcluding": "7.0.11",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACB90095-374D-427A-899E-1607155BB924",
"versionEndExcluding": "7.3.3",
"versionStartIncluding": "7.3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@mongodb.com"
}