{"id":"CVE-2023-1409","summary":"Certificate validation issue in MongoDB Server running on Windows or macOS","details":"If the MongoDB Server running on Windows or macOS is configured to use TLS with a specific set of configuration options that are already known to work securely in other platforms (e.g. Linux), it is possible that client certificate validation may not be in effect, potentially allowing client to establish a TLS connection with the server that supplies any certificate.\n\nThis issue affect all MongoDB Server v6.3 versions, MongoDB Server v5.0 versions v5.0.0 to v5.0.14 and all MongoDB Server v4.4 versions.","aliases":["BIT-mongodb-2023-1409"],"modified":"2026-08-12T14:50:34.770388Z","published":"2023-08-23T15:21:43.150Z","database_specific":{"cna_assigner":"mongodb","cwe_ids":["CWE-295"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1409.json","unresolved_ranges":[{"extracted_events":[{"introduced":"6.3"},{"last_affected":"6.3.2"},{"introduced":"5.0"},{"last_affected":"5.0.14"},{"introduced":"4.4"},{"last_affected":"4.4.23"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://jira.mongodb.org/browse/SERVER-73662"},{"type":"WEB","url":"https://jira.mongodb.org/browse/SERVER-77028"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/1xxx/CVE-2023-1409.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1409"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230921-0007/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mongodb/mongo","events":[{"introduced":"563487e100c4215e2dce98d0af2a6a5a2d67c5cf"},{"fixed":"36c047f935fd86b2d5ac4c4f5189e52daa044966"},{"introduced":"1184f004a99660de6f5e745573419bda8a28c0e9"},{"last_affected":"1b3b0073a0b436a8a502b612f24fb2bd572772e5"},{"introduced":"e61bf27c2f6a83fed36e5a13c008a32d563babe2"},{"fixed":"202ad4fda2618c652e35f5981ef2f903d8dd1f1a"},{"introduced":"ce2089f7f6cd781ab84cdc54e17082982cca609f"},{"last_affected":"3427190e54b188e0e0b2b38399e95edfa31c2c9e"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.4.0"},{"fixed":"4.4.23"},{"introduced":"5.0.0"},{"last_affected":"5.0.14"},{"introduced":"6.0.0"},{"fixed":"6.0.7"},{"introduced":"6.3.0"},{"last_affected":"6.3.2"}]}}],"versions":["r6.3.2-rc1","r6.3.2","r6.3.2-rc0","r4.4.22-rc2","r4.4.22","r4.4.22-rc1","r4.4.22-rc0","r6.0.6-rc1","r6.0.6","r6.0.6-rc0","r6.3.1-rc1","r6.3.1","r4.4.21-rc0","r4.4.21","r6.3.1-rc0","r6.3.0","r4.4.20-rc0","r4.4.20","r6.0.5-rc1","r6.0.5","r6.0.5-rc0","r6.0.4-rc1","r4.4.19-rc2","r4.4.19","r4.4.19-rc1","r4.4.19-rc0","r6.0.4-rc0","r6.0.4","r5.0.14-rc0","r5.0.14","r6.0.3-rc2","r6.0.3-rc1","r6.0.3","r4.4.18-rc0","r4.4.18","r6.0.3-rc0","r4.4.17-rc2","r4.4.17","r6.0.2-rc1","r6.0.2","r5.0.13-rc0","r5.0.13","r4.4.17-rc1","r4.4.17-rc0","r5.0.12-rc0","r5.0.12","r6.0.2-rc0","r5.0.11-rc1","r5.0.11","r5.0.11-rc0","r4.4.16-rc0","r4.4.16","r6.0.1-rc0","r6.0.1","r5.0.10-rc0","r5.0.10","r6.0.0","r4.4.15-rc0","r4.4.15","r5.0.9-rc1","r5.0.9","r5.0.9-rc0","r4.4.14-rc0","r4.4.14","r5.0.8-rc0","r5.0.8","r5.0.7-rc1","r5.0.7","r5.0.7-rc0","r4.4.13-rc0","r4.4.13","r5.0.6-rc2","r5.0.6","r5.0.6-rc1","r4.4.12-rc1","r4.4.12","r5.0.6-rc0","r4.4.12-rc0","r4.4.11-rc1","r4.4.11","r5.0.5-rc0","r5.0.5","r4.4.11-rc0","r5.0.4-rc0","r5.0.4","r4.4.10-rc0","r4.4.10","r4.4.9-rc1","r4.4.9","r5.0.3-rc2","r5.0.3","r5.0.3-rc1","r4.4.9-rc0","r5.0.3-rc0","r4.4.8-rc0","r4.4.8","r5.0.2-rc0","r5.0.2","r4.4.7-rc1","r4.4.7","r5.0.1-rc0","r5.0.1","r5.0.0","r4.4.7-rc0","r4.4.6-rc0","r4.4.6","r4.4.5-rc0","r4.4.5","r4.4.4-rc1","r4.4.4","r4.4.4-rc0","r4.4.3-rc0","r4.4.3","r4.4.2-rc1","r4.4.2","r4.4.2-rc0","r4.4.1-rc3","r4.4.1","r4.4.1-rc2","r4.4.1-rc1","r4.4.1-rc0","r4.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-1409.json","vanir_signatures_modified":"2026-08-12T14:50:34Z","vanir_signatures":[{"target":{"file":"src/mongo/db/pipeline/document_source_writer.h","function":"doGetNext"},"deprecated":false,"digest":{"function_hash":"195833968822288153278355484592571100031","length":1812},"id":"CVE-2023-1409-45e3d9d2","signature_type":"Function","signature_version":"v1","source":"https://github.com/mongodb/mongo/commit/36c047f935fd86b2d5ac4c4f5189e52daa044966"},{"source":"https://github.com/mongodb/mongo/commit/36c047f935fd86b2d5ac4c4f5189e52daa044966","target":{"file":"src/mongo/db/pipeline/document_source_writer.h"},"deprecated":false,"digest":{"line_hashes":["248940352725811230760535097933817976911","188772621648876426283820446312135152753","126731850152722157444095119326038365881","153770883029649971279403676729242997305","206523451452853977828501845752839463726","233400954344776929454613197912929344377","216411236188289350219335562320885826709","92779791213540355878940379398351403466","271073076238223298336157336962272301235"],"threshold":0.9},"id":"CVE-2023-1409-f8e72e64","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}