#VU111863 Missing Authorization in MongoDB - CVE-2024-6375
Published: June 24, 2025
MongoDB
MongoDB, Inc.
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the command for refining a collection shard key is missing an authorization check. A remote attacker can cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels.