Skip to main content
interlace
Plugin: mongodb-securityRules

require-tls-connection

Requires TLS/SSL encryption for MongoDB connections in production environments.

⚠️ This rule warns by default in the recommended config.

Quick Summary

AspectDetails
CWE ReferenceCWE-295 (Improper Certificate Validation)
OWASPA02:2021 - Cryptographic Failures
SeverityHigh (CVSS: 7.4)
CategorySecurity

Rule Details

MongoDB connections without TLS are vulnerable to:

  • Man-in-the-Middle (MitM) attacks
  • Credential interception
  • Data exfiltration during transit

❌ Incorrect

// No TLS enabled
mongoose.connect('mongodb://localhost:27017/db');

// Explicit TLS disabled
mongoose.connect(uri, { tls: false });

// Legacy ssl option disabled
mongoose.connect(uri, { ssl: false });

✅ Correct

const x = 1;

Receiver Requirement

A .connect() is not evidence of MongoDB. Redis clients, TypeORM query runners and pino transports all have one, and naming another database's connection "MongoDB" is worse than staying silent. This rule only fires when the receiver is bound to a mongodb/mongoose import, is a new MongoClient(...), or is named mongo*.

// ✅ Not reported — Redis
const client = createClient({ url: REDIS_URL });
await client.connect();

// ✅ Not reported — TypeORM
const queryRunner = this.repository.manager.connection.createQueryRunner();
await queryRunner.connect();

allowInTests (on by default) also covers files under test/, tests/, __tests__/, __mocks__/, e2e/ and fixtures/ directories, not just *.test.ts / *.spec.ts — testcontainers helpers are not production connections.

Known False Positives

Local Development

// FP: Intentionally no TLS for local dev
mongoose.connect('mongodb://localhost:27017/devdb');

Workaround: Use allowInTests: true or configure environment-specific rules.

Known False Negatives

Dynamic Configuration

// ❌ NOT DETECTED
const options = getConfig();
mongoose.connect(uri, options); // TLS may or may not be enabled

When Not To Use It

  • Local development with Docker containers
  • Test environments with ephemeral databases
  • Environments where TLS is handled at network level (VPC, SSH tunnel)

References

⚙️ Options

OptionTypeDefaultDescription
allowInTestsbooleantrueSkip this rule in *.test.* / *.spec.* files

Did this rule catch something? Star the repo to get new CWE coverage as we ship it — or follow the AI-code-security benchmarks behind these rules.