CVE-2024-1351
MongoDB Server may allow successful untrusted connection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28.
Required Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.
Bajo ciertas configuraciones de --tlsCAFile y tls.CAFile, el servidor MongoDB puede omitir la validación de certificados de pares, lo que puede resultar en conexiones que no son de confianza para tener éxito. Esto puede reducir efectivamente las garantías de seguridad proporcionadas por TLS y abrir conexiones que deberían haberse cerrado debido a una validación fallida del certificado. Este problema afecta a las versiones de MongoDB Server v7.0 anteriores a 7.0.5 incluida, a las versiones de MongoDB Server v6.0 anteriores a 6.0.13 incluida, a las versiones de MongoDB Server v5.0 anteriores a 5.0.24 incluida y a MongoDB Server v4.4 Versiones anteriores a la 4.4.28 incluida. Configuración requerida: un proceso de servidor permitirá que las conexiones entrantes omitan la validación del certificado de pares si el proceso del servidor se inició con TLS habilitado (net.tls.mode configurado en enableTLS, preferTLS o requireTLS) y sin un archivo net.tls.CAFile configurado.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-02-08 CVE Reserved
- 2024-03-07 CVE Published
- 2024-06-11 EPSS Updated
- 2024-08-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (6)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
MongoDB Inc Search vendor "MongoDB Inc" | MongoDB Server Search vendor "MongoDB Inc" for product "MongoDB Server" | >= 7.0.0 <= 7.0.5 Search vendor "MongoDB Inc" for product "MongoDB Server" and version " >= 7.0.0 <= 7.0.5" | en |
Affected
| ||||||
MongoDB Inc Search vendor "MongoDB Inc" | MongoDB Server Search vendor "MongoDB Inc" for product "MongoDB Server" | >= 6.0.0 <= 6.0.13 Search vendor "MongoDB Inc" for product "MongoDB Server" and version " >= 6.0.0 <= 6.0.13" | en |
Affected
| ||||||
MongoDB Inc Search vendor "MongoDB Inc" | MongoDB Server Search vendor "MongoDB Inc" for product "MongoDB Server" | >= 5.0.0 <= 5.0.24 Search vendor "MongoDB Inc" for product "MongoDB Server" and version " >= 5.0.0 <= 5.0.24" | en |
Affected
| ||||||
MongoDB Inc Search vendor "MongoDB Inc" | MongoDB Server Search vendor "MongoDB Inc" for product "MongoDB Server" | >= 4.4.0 <= 4.4.28 Search vendor "MongoDB Inc" for product "MongoDB Server" and version " >= 4.4.0 <= 4.4.28" | en |
Affected
|