CVE-2020-7924

MEDIUM

MongoDB Database Tools <100.2.0, Mongomirror <0.6.0 - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.

References (1)

Core 1
Core References
Issue Tracking, Patch, Vendor Advisory x_refsource_misc
https://jira.mongodb.org/browse/TOOLS-2587

Scores

CVSS v3 4.2
EPSS 0.0069
EPSS Percentile 48.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-295
Status published
Products (3)
mongodb/database_tools 3.6.5 - 3.6.21
mongodb/mongo-tools 100.0.0 - 100.2.0Go
mongodb/mongomirror < 0.6.0
Published Apr 12, 2021
Tracked Since Feb 18, 2026