Описание
When tlsInsecure=False appears in a connection string, certificate validation is disabled.
This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5
A certificate validation flaw has been discovered in the MongoDB Rust Driver. When tlsInsecure=False appears in a connection string, certificate validation is disabled. This behavior interacts with other configuration options and may result in unexpected tls handling behavior.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-operator-bundle | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-rhel9-operator | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/eventrouter-rhel9 | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/fluentd-rhel9 | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/log-file-metric-exporter-rhel9 | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-view-plugin-rhel9 | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/vector-rhel9 | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-operator-bundle | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/cluster-logging-rhel9-operator | Will not fix | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/eventrouter-rhel9 | Will not fix |
Показывать по
Дополнительная информация
Статус:
8 High
CVSS3
Связанные уязвимости
When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5
MongoDB Rust Driver has certificate validation disabled when `tlsInsecure=False` appears in connection string
8 High
CVSS3