Improper Certificate Validation in MongoDB - CVE-2023-1409

 

Improper Certificate Validation in MongoDB - CVE-2023-1409

Published: November 20, 2023


Vulnerability identifier: #VU83270
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-1409
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify data on the system.

The vulnerability exists if the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux). A remote attacker can exploit vulnerability to modify data on the system.


Affected software

MongoDB
IBM Spectrum Protect Plus
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Storage Copy Data Management

How to mitigate CVE-2023-1409

Install updates from vendor's website.

MongoDB - addressed in versions 4.4.23, 5.0.15, 6.0.7
IBM Spectrum Protect Plus - update to 10.1.17.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
Storage Copy Data Management - update to 2.2.23.0
IBM Automation Decision Services - update to 23.0.1 IF003

External References

Related Security Bulletins