A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled
History

Tue, 01 Apr 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 12:15:00 +0000

Type Values Removed Values Added
Description A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled
Title MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked
First Time appeared Mongodb
Mongodb mongodb
Weaknesses CWE-299
CPEs cpe:2.3:a:mongodb:mongodb:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.14:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.15:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.16:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.17:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.18:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.19:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.20:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.21:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.22:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.23:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.24:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.25:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.26:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.27:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.28:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.29:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.30:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:5.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.14:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.15:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.16:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.17:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.18:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.19:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:6.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.11:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.12:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.13:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.14:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.15:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.3:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.5:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.6:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.7:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.8:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:7.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:8.0.0:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:8.0.1:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:8.0.2:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:8.0.3:*:*:*:*:*:*:*
Vendors & Products Mongodb
Mongodb mongodb
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2025-04-01T13:03:02.701Z

Reserved: 2025-04-01T09:16:34.872Z

Link: CVE-2025-3085

cve-icon Vulnrichment

Updated: 2025-04-01T13:02:51.563Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-01T12:15:16.187

Modified: 2025-04-01T20:26:11.547

Link: CVE-2025-3085

cve-icon Redhat

No data.