CVE-2024-1351
MongoDB Server: peer certificate validation skipped when TLS is enabled without a CA file
Technology
MongoDB
CVSS Score
9.8 / 10.0
Affected Versions
7.0.5 and earlier; 6.0.13 and earlier; 5.0.24 and earlier; 4.4.28 and earlier
Upstream Fix
7.0.6; 6.0.14; 5.0.25; 4.4.29
Published
March 7, 2024
OSSeva Coverage
Fixed upstream
Description
Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation, so untrusted connections can succeed. A server is affected if it was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS or requireTLS) and without a net.tls.CAFile configured. NVD scores the record 9.8; MongoDB scores it 8.8.
Is your MongoDB deployment affected?
If you're running 7.0.5 and earlier; 6.0.13 and earlier; 5.0.24 and earlier; 4.4.28 and earlier, you need this patch. Book a discovery call to get covered.