PT-2025-14098 · Mongodb+2 · Mongodb Server+3

Published

2024-10-01

·

Updated

2025-09-25

·

CVE-2025-3085

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MongoDB Server versions prior to 5.0.31 MongoDB Server versions prior to 6.0.20 MongoDB Server versions prior to 7.0.16 MongoDB Server versions prior to 8.0.4
Description A MongoDB server running on Linux with TLS and CRL revocation status checking enabled fails to check the revocation status of the intermediate certificates in the peer's certificate chain. This may lead to improper authentication, particularly in cases of MONGODB-X509, which is not enabled by default. The issue may also affect intra-cluster authentication.
Recommendations For versions prior to 5.0.31, update to version 5.0.31 or later. For versions prior to 6.0.20, update to version 6.0.20 or later. For versions prior to 7.0.16, update to version 7.0.16 or later. For versions prior to 8.0.4, update to version 8.0.4 or later.

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2025-5420
ALT-PU-2025-5457
ALT-PU-2025-5464
ALT-PU-2025-5545
BDU:2025-03885
BIT-MONGODB-2025-3085
CVE-2025-3085

Affected Products

Alt Linux
Mongodb Server
Mongodb
Red Os