CVE-2024-3371
Mongodb Compass 1.35.0 – 1.42.1
Raw vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:LSummary
CVE-2024-3371 is a high-severity Trust of System Event Data (CWE-360) vulnerability in Mongodb Compass. Its CVSS base score is 7.1 (High).
Operationally, ranked at the 14th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-31960
Vulnerability Data
MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Logging can capture event data but does not inherently validate its authenticity against spoofing.
Monitoring activities may detect anomalies in event data but do not guarantee the trustworthiness of the source.
Clock synchronization supports event correlation but does not prevent spoofed event data.
Network security controls can limit spoofing vectors but do not fully address trust in system event data.
Cryptography can protect event integrity and authenticity but is not explicitly required by the control for this purpose.
Secure architecture principles can include event validation mechanisms but do not mandate them.