6.4
CVSSv2

CVE-2020-7924

Published: 12/04/2021 Updated: 21/04/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions before 3.6.21; 4.0 versions before 4.0.21; 4.2 versions before 4.2.11; 100 versions before 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mongodb database tools

mongodb mongomirror

Vendor Advisories

Debian Bug report logs - #988021 mongo-tools: CVE-2020-7924 Package: src:mongo-tools; Maintainer for src:mongo-tools is Debian MongoDB Maintainers <team+mongodb@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 3 May 2021 19:57:02 UTC Severity: grave Tags: security, upstream Foun ...