When tlsInsecure=False appears in a connection string, certificate validation is disabled.
This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5
Metrics
Affected Vendors & Products
References
History
Mon, 20 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb rust-driver |
|
| Vendors & Products |
Mongodb
Mongodb rust-driver |
Wed, 15 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Oct 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5 | |
| Title | Configuration may unexpectedly disable certificate validation | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published: 2025-10-13T16:22:57.417Z
Updated: 2025-10-21T03:55:19.647Z
Reserved: 2025-10-13T16:15:52.158Z
Link: CVE-2025-11695
Updated: 2025-10-14T14:29:13.207Z
Status : Awaiting Analysis
Published: 2025-10-13T17:15:34.190
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-11695