Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2024-8013 Details

Description

A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue affects mongocryptd binary (v5.0 versions prior to 5.0.29, v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) and mongo_crypt_v1.so shared libraries (v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) released alongside MongoDB Enterprise Server versions.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-319Cleartext Transmission of Sensitive Information[email protected]
CWE-319Cleartext Transmission of Sensitive Information[email protected]

Affected Products

ProductVersions
mongodb mongo crypt v1.so
>= 6.0.0, < 6.0.17
>= 7.0.0, < 7.0.12
>= 7.3.0, < 7.3.4

CPE

  • cpe:2.3:a:mongodb:mongo_crypt_v1.so:*:*:*:*:*:mongodb:*:*

Remediation

  • No remediation found in references.
mongodb mongocryptd
>= 5.0.0, < 5.0.29
>= 6.0.0, < 6.0.17
>= 7.0.0, < 7.0.12
>= 7.3.0, < 7.3.4

CPE

  • cpe:2.3:a:mongodb:mongocryptd:*:*:*:*:*:mongodb:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2024-8013
NVD Published Date:
Oct 28, 2024
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2024-8013 Details - Not Deferred