CVE-2020-1929
HIGHApache Beam 2.10.0-2.16.0 - Improper Certificate Validation in MongoDB Connector
Title source: llmDescription
The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This exclusion also gets registered globally which disables trust checking for any code running in the same JVM.
References (1)
Core 1
Core References
Mailing List, Vendor Advisory mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/rdd0e85b71bf0274471b40fa1396d77f7b2d1165eaea4becbdc69aa04%40%3Cuser.beam.apache.org%3E
Scores
CVSS v3
7.5
EPSS
0.0040
EPSS Percentile
60.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-295
Status
published
Products (2)
apache/beam
2.10.0 - 2.16.0
org.apache.beam/beam-sdks-java-io-mongodb
2.10.0 - 2.17.0Maven
Published
Jan 15, 2020
Tracked Since
Feb 18, 2026