Certificate validation issue in MongoDB Server running on Windows or macOS
CVE-2023-1409
7.5HIGH
Key Information:
- Vendor
MongoDB
- Status
- Vendor
- CVE Published:
- 23 August 2023
What is CVE-2023-1409?
A configuration flaw in the MongoDB Server on Windows and macOS platforms enables the potential risk of bypassing client certificate validation when using TLS with certain settings. This vulnerability may allow unauthorized clients to connect to the server as valid entities, compromising the integrity of secure communications. Affected versions include MongoDB Server v6.3, v5.0 from v5.0.0 to v5.0.14, and all MongoDB Server v4.4 builds.
Affected Version(s)
MongoDB Server 6.3 <= 6.3.2
MongoDB Server 5.0 <= 5.0.14
MongoDB Server 4.4 <= 4.4.23