Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2024-1351

MongoDB Server: peer certificate validation skipped when TLS is enabled without a CA file

Technology

MongoDB

CVSS Score

9.8 / 10.0

Affected Versions

7.0.5 and earlier; 6.0.13 and earlier; 5.0.24 and earlier; 4.4.28 and earlier

Upstream Fix

7.0.6; 6.0.14; 5.0.25; 4.4.29

Published

March 7, 2024

OSSeva Coverage

Fixed upstream

Description

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation, so untrusted connections can succeed. A server is affected if it was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS or requireTLS) and without a net.tls.CAFile configured. NVD scores the record 9.8; MongoDB scores it 8.8.

Upstream record: NVD · CVE.org

Is your MongoDB deployment affected?

If you're running 7.0.5 and earlier; 6.0.13 and earlier; 5.0.24 and earlier; 4.4.28 and earlier, you need this patch. Book a discovery call to get covered.