CVE-2025-3085
MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4.
Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled
A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-04-01 CVE Reserved
- 2025-04-01 CVE Published
- 2025-04-01 CVE Updated
- 2025-04-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-299: Improper Check for Certificate Revocation
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
MongoDB Inc Search vendor "MongoDB Inc" | MongoDB Server Search vendor "MongoDB Inc" for product "MongoDB Server" | >= 5.0.0 < 5.0.31 Search vendor "MongoDB Inc" for product "MongoDB Server" and version " >= 5.0.0 < 5.0.31" | en |
Affected
| ||||||
MongoDB Inc Search vendor "MongoDB Inc" | MongoDB Server Search vendor "MongoDB Inc" for product "MongoDB Server" | >= 6.0.0 < 6.0.20 Search vendor "MongoDB Inc" for product "MongoDB Server" and version " >= 6.0.0 < 6.0.20" | en |
Affected
| ||||||
MongoDB Inc Search vendor "MongoDB Inc" | MongoDB Server Search vendor "MongoDB Inc" for product "MongoDB Server" | >= 7.0.0 < 7.0.16 Search vendor "MongoDB Inc" for product "MongoDB Server" and version " >= 7.0.0 < 7.0.16" | en |
Affected
|