Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions before 3.6.21; 4.0 versions before 4.0.21; 4.2 versions before 4.2.11; 100 versions before 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mongodb mongomirror |
||
mongodb database tools |