Missing Authorization in MongoDB - CVE-2024-6375
Published: June 24, 2025
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the command for refining a collection shard key is missing an authorization check. A remote attacker can cause the command to run directly on a shard, leading to either degradation of query performance, or to revealing chunk boundaries through timing side channels.
Affected software
IBM Spectrum Protect Plus
How to mitigate CVE-2024-6375
IBM Spectrum Protect Plus - update to 10.1.17.1