Does anyone know it the verion 9.4.8 fixed the CVE-2025-3085 of the build in MongoDB?
MongoDB 5.0.x < 5.0.31 / 6.0.x < 6.0.20 / 7.0.x < 7.0.16 / 8... | Tenable®
Thank you
@drychan Yes, it was fixed on Splunk Enterprise 9.4.8, the bundled MongoDB versions are patched and CVE‑2025‑3085 is fixed with this version.
We have upgraded to version 9.4.8 and the issue was not fixed.
Is there any suggestion?
Hi @drychan
For Splunk Enterprise 10.2.0, 10.0.3, and 9.4.8 for Linux, Splunk Enterprise upgraded the MongoDB versions to 8.0.10-patch-67e1e610f737760007cfe08b, 7.0.18-patch-694341b1e05e2a0007bc4524, 6.0.27, 5.0.32, and 4.4.30.
All these versions are greater than the version affected by CVE-2025-3085 (see https://jira.mongodb.org/browse/SERVER-95445 for affected version).
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing