MongoDB Rust Driver
cpe:2.3:a:mongodb:rust_driver:*:*:*:*:mongodb:*:*
- < 3.2.5
A vulnerability exists in the MongoDB Rust Driver in versions prior to 3.2.5, where disabling certificate validation can be achieved by setting tlsInsecure=False in the connection string. This flaw allows for insecure TLS connections by bypassing proper certificate verification.
Exploiting this vulnerability leads to insecure TLS connections, allowing potential man-in-the-middle attacks by disabling certificate validation.
Users can upgrade to MongoDB Rust Driver version 3.2.5 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.