vulnerability

FreeBSD: VID-a8448963-e6f5-11ee-a784-dca632daf43b (CVE-2024-1351): databases/mongodb* -- Improper Certificate Validation

Severity
8
CVSS
(AV:A/AC:L/Au:N/C:C/I:C/A:C)
Published
Mar 20, 2024
Added
Dec 10, 2025
Modified
Dec 10, 2025

Description

MongoDB, Inc. reports: A security vulnerability was found where a server process running MongoDB 3.2.6 or later will allow incoming connections to skip peer certificate validation if the server process was started with TLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and without a net.tls.CAFile configured (CVE-2024-1351).

Solutions

freebsd-upgrade-package-mongodb44freebsd-upgrade-package-mongodb50freebsd-upgrade-package-mongodb60freebsd-upgrade-package-mongodb70
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.