6.5
CVSSv3

CVE-2020-7924

Published: 12/04/2021 Updated: 13/02/2024
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 6.5 | Impact Score: 2.5 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions before 3.6.21; 4.0 versions before 4.0.21; 4.2 versions before 4.2.11; 100 versions before 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mongodb mongomirror

mongodb database tools

Vendor Advisories

Debian Bug report logs - #988021 mongo-tools: CVE-2020-7924 Package: src:mongo-tools; Maintainer for src:mongo-tools is Debian MongoDB Maintainers <team+mongodb@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 3 May 2021 19:57:02 UTC Severity: grave Tags: security, upstream Foun ...