Certificate validation issue in MongoDB Server running on Windows or macOS
CVE-2023-1409
7.5HIGH
Summary
A configuration flaw in the MongoDB Server on Windows and macOS platforms enables the potential risk of bypassing client certificate validation when using TLS with certain settings. This vulnerability may allow unauthorized clients to connect to the server as valid entities, compromising the integrity of secure communications. Affected versions include MongoDB Server v6.3, v5.0 from v5.0.0 to v5.0.14, and all MongoDB Server v4.4 builds.
Affected Version(s)
MongoDB Server 6.3 <= 6.3.2
MongoDB Server 5.0 <= 5.0.14
MongoDB Server 4.4 <= 4.4.23
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved