CVE-2024-1351
Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28.
Required Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.50%
- Percentil entre todas las CVEs puntuadas: 41
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-295
- CWE-295
Referencias
- https://jira.mongodb.org/browse/SERVER-72839
- https://security.netapp.com/advisory/ntap-20240524-0010/
- https://www.mongodb.com/docs/manual/release-notes/4.4/#4.4.29---february-28--2024
- https://www.mongodb.com/docs/manual/release-notes/7.0/#7.0.6---feb-28--2024
- https://www.mongodb.com/docs/v5.0/release-notes/5.0/#5.0.25---february-28--2024
- https://www.mongodb.com/docs/v6.0/release-notes/6.0/#6.0.14---feb-28--2024
- https://jira.mongodb.org/browse/SERVER-72839
- https://security.netapp.com/advisory/ntap-20240524-0010/
- https://www.mongodb.com/docs/manual/release-notes/4.4/#4.4.29---february-28--2024
- https://www.mongodb.com/docs/manual/release-notes/7.0/#7.0.6---feb-28--2024
- https://www.mongodb.com/docs/v5.0/release-notes/5.0/#5.0.25---february-28--2024
- https://www.mongodb.com/docs/v6.0/release-notes/6.0/#6.0.14---feb-28--2024
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-1351",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-1351",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-03-07T18:56:20.004972Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cna@mongodb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cna@mongodb.com",
"affectedData": [
{
"vendor": "MongoDB Inc",
"product": "MongoDB Server",
"versions": [
{
"status": "affected",
"version": "7.0",
"versionType": "custom",
"lessThanOrEqual": "7.0.5"
},
{
"status": "affected",
"version": "6.0",
"versionType": "custom",
"lessThanOrEqual": "6.0.13"
},
{
"status": "affected",
"version": "5.0",
"versionType": "custom",
"lessThanOrEqual": "5.0.24"
},
{
"status": "affected",
"version": "4.4",
"versionType": "custom",
"lessThanOrEqual": "4.4.28"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*"
],
"vendor": "mongodb",
"product": "mongodb",
"versions": [
{
"status": "affected",
"version": "7.0",
"versionType": "custom",
"lessThanOrEqual": "7.0.5"
},
{
"status": "affected",
"version": "6.0",
"versionType": "custom",
"lessThanOrEqual": "6.0.13"
},
{
"status": "affected",
"version": "5.0",
"versionType": "custom",
"lessThanOrEqual": "5.0.24"
},
{
"status": "affected",
"version": "4.4",
"versionType": "custom",
"lessThanOrEqual": "4.4.28"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-03-07T17:15:12.740",
"references": [
{
"url": "https://jira.mongodb.org/browse/SERVER-72839",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "cna@mongodb.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240524-0010/",
"tags": [
"Third Party Advisory"
],
"source": "cna@mongodb.com"
},
{
"url": "https://www.mongodb.com/docs/manual/release-notes/4.4/#4.4.29---february-28--2024",
"tags": [
"Broken Link"
],
"source": "cna@mongodb.com"
},
{
"url": "https://www.mongodb.com/docs/manual/release-notes/7.0/#7.0.6---feb-28--2024",
"tags": [
"Release Notes"
],
"source": "cna@mongodb.com"
},
{
"url": "https://www.mongodb.com/docs/v5.0/release-notes/5.0/#5.0.25---february-28--2024",
"tags": [
"Release Notes"
],
"source": "cna@mongodb.com"
},
{
"url": "https://www.mongodb.com/docs/v6.0/release-notes/6.0/#6.0.14---feb-28--2024",
"tags": [
"Release Notes"
],
"source": "cna@mongodb.com"
},
{
"url": "https://jira.mongodb.org/browse/SERVER-72839",
"tags": [
"Issue Tracking",
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240524-0010/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mongodb.com/docs/manual/release-notes/4.4/#4.4.29---february-28--2024",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mongodb.com/docs/manual/release-notes/7.0/#7.0.6---feb-28--2024",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mongodb.com/docs/v5.0/release-notes/5.0/#5.0.25---february-28--2024",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mongodb.com/docs/v6.0/release-notes/6.0/#6.0.14---feb-28--2024",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "cna@mongodb.com",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.5, MongoDB Server v6.0 versions prior to and including 6.0.13, MongoDB Server v5.0 versions prior to and including 5.0.24 and MongoDB Server v4.4 versions prior to and including 4.4.28.\n\nRequired Configuration : A server process will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured."
},
{
"lang": "es",
"value": "Bajo ciertas configuraciones de --tlsCAFile y tls.CAFile, el servidor MongoDB puede omitir la validación de certificados de pares, lo que puede resultar en conexiones que no son de confianza para tener éxito. Esto puede reducir efectivamente las garantías de seguridad proporcionadas por TLS y abrir conexiones que deberían haberse cerrado debido a una validación fallida del certificado. Este problema afecta a las versiones de MongoDB Server v7.0 anteriores a 7.0.5 incluida, a las versiones de MongoDB Server v6.0 anteriores a 6.0.13 incluida, a las versiones de MongoDB Server v5.0 anteriores a 5.0.24 incluida y a MongoDB Server v4.4 Versiones anteriores a la 4.4.28 incluida. Configuración requerida: un proceso de servidor permitirá que las conexiones entrantes omitan la validación del certificado de pares si el proceso del servidor se inició con TLS habilitado (net.tls.mode configurado en enableTLS, preferTLS o requireTLS) y sin un archivo net.tls.CAFile configurado."
}
],
"lastModified": "2026-06-17T07:04:02.423",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6BEEC634-F69A-404A-A867-F38A31137F31",
"versionEndExcluding": "4.4.29",
"versionStartIncluding": "4.4.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C4D47D83-31AE-459D-B0EC-3F5184EF1912",
"versionEndExcluding": "5.0.25",
"versionStartIncluding": "5.0.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB3D23E4-41F4-4AAF-8B09-401BF735740E",
"versionEndExcluding": "6.0.14",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D7A1437-1CC0-4ECC-AE42-9F32E84282A5",
"versionEndExcluding": "7.0.6",
"versionStartIncluding": "7.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netapp:astra_control_center:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EC5EBD2A-32A3-46D5-B155-B44DCB7F6902"
},
{
"criteria": "cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*",
"vulnerable": true,
"matchCriteriaId": "5333B745-F7A3-46CB-8437-8668DB08CD6F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@mongodb.com"
}