Логотип exploitDog
bind: "CVE-2025-3085"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-3085"

Количество 8

Количество 8

ubuntu логотип

CVE-2025-3085

3 месяца назад

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2025-3085

3 месяца назад

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2025-3085

3 месяца назад

A MongoDB server under specific conditions running on Linux with TLS a ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-v8j7-gw8h-m2j4

3 месяца назад

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2025-03885

9 месяцев назад

Уязвимость класса SSLManagerOpenSSL системы управления базами данных MongoDB, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20250505-09

около 2 месяцев назад

Множественные уязвимости mongodb-org

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20250505-08

около 2 месяцев назад

Множественные уязвимости mongodb-org

CVSS3: 8.1
EPSS: Низкий
redos логотип

ROS-20250505-07

около 2 месяцев назад

Множественные уязвимости mongodb-org

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-3085

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled

CVSS3: 8.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-3085

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled

CVSS3: 8.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-3085

A MongoDB server under specific conditions running on Linux with TLS a ...

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-v8j7-gw8h-m2j4

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4. Required Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled

CVSS3: 8.1
0%
Низкий
3 месяца назад
fstec логотип
BDU:2025-03885

Уязвимость класса SSLManagerOpenSSL системы управления базами данных MongoDB, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 8.1
0%
Низкий
9 месяцев назад
redos логотип
ROS-20250505-09

Множественные уязвимости mongodb-org

CVSS3: 8.1
около 2 месяцев назад
redos логотип
ROS-20250505-08

Множественные уязвимости mongodb-org

CVSS3: 8.1
около 2 месяцев назад
redos логотип
ROS-20250505-07

Множественные уязвимости mongodb-org

CVSS3: 8.1
около 2 месяцев назад

Уязвимостей на страницу