CVE-2025-3085
MongoDB Server: intermediate certificates not checked for revocation on Linux
Technology
MongoDB
CVSS Score
9.8 / 10.0
Affected Versions
8.0 before 8.0.4; 7.0 before 7.0.16; 6.0 before 6.0.20; 5.0 before 5.0.31
Upstream Fix
8.0.4; 7.0.16; 6.0.20; 5.0.31
Published
April 1, 2025
OSSeva Coverage
Fixed upstream
Description
On Linux with TLS and CRL revocation checking enabled, MongoDB Server fails to check the revocation status of intermediate certificates in the peer's chain. With MONGODB-X509 authentication, which is not enabled by default, this may lead to improper authentication, and it may also affect intra-cluster authentication. NVD scores the record 9.8; MongoDB scores it 8.1.
Is your MongoDB deployment affected?
If you're running 8.0 before 8.0.4; 7.0 before 7.0.16; 6.0 before 6.0.20; 5.0 before 5.0.31, you need this patch. Book a discovery call to get covered.