Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11695

Опубликовано: 13 окт. 2025
Источник: redhat
CVSS3: 8

Описание

When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5

A certificate validation flaw has been discovered in the MongoDB Rust Driver. When tlsInsecure=False appears in a connection string, certificate validation is disabled. This behavior interacts with other configuration options and may result in unexpected tls handling behavior.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/log-file-metric-exporter-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2403578mongodb: MongoDB rust driver may unexpectedly disable certificate validation

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
11 месяцев назад

When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5

CVSS3: 8
github
11 месяцев назад

MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string

8 High

CVSS3