QID 379482
Date Published: 2024-03-26
QID 379482: MongoDB Certificate Validation Issue (SERVER-72839)
MongoDB is an open-source document database, and NoSQL database.
Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed.
Affected Versions:
MongoDB Server v7.0 versions v7.0.0 to v7.0.5
MongoDB Server v6.0 versions v6.0.0 to v6.0.13
MongoDB Server v5.0 versions v5.0.0 to v5.0.24
MongoDB Server v4.0 versions v4.4.0 to v 4.4.28
pQID Detection Logic:(Authenticated)
This QID checks for vulnerable versions of MongoDB installed on the target.
Note: Atlas clusters are not affected by this vulnerability.
On vulnerable versions of MongoDB,MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed.
For more information visit SERVER-72839 and SERVER-73662
- SERVER-72839 -
jira.mongodb.org/browse/SERVER-72839
CVEs related to QID 379482
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SERVER-72839 |
|