CVE-2025-3085
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-3085 is a vulnerability affecting specific configurations of MongoDB servers running on Linux. When TLS and Certificate Revocation List (CRL) checking are enabled, these servers fail to verify the revocation status of intermediate certificates in the peer's certificate chain. This can lead to improper authentication in MongoDB's X509 module, which is not enabled by default. Intra-cluster authentication might also be impacted. Affected versions include MongoDB Server v5.0 before 5.0.31, v6.0 before 6.0.20, v7.0 before 7.0.16, and v8.0 before 8.0.4. MongoDB servers on Linux operating systems with CRL revocation status checking activated are susceptible to this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress