CVE-2019-2388

In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1 version 4.1.5.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mongodb:ops_manager:4.0.9:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:ops_manager:4.0.10:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:ops_manager:4.1.5:*:*:*:*:*:*:*

History

21 Nov 2024, 04:40

Type Values Removed Values Added
References () https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#onprem-server-4.0.11 - () https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#onprem-server-4.0.11 -
CVSS v2 : 5.0
v3 : 5.3
v2 : 5.0
v3 : 5.8

23 Jan 2024, 15:15

Type Values Removed Values Added
References
  • {'url': 'https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-0', 'name': 'https://docs.opsmanager.mongodb.com/current/release-notes/application/#onprem-server-4-0', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • () https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#onprem-server-4.0.11 -

19 Jun 2023, 16:15

Type Values Removed Values Added
Summary In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1 version 4.1.5. In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1 version 4.1.5.

Information

Published : 2020-05-13 17:15

Updated : 2024-11-21 04:40


NVD link : CVE-2019-2388

Mitre link : CVE-2019-2388

CVE.ORG link : CVE-2019-2388


JSON object : View

Products Affected

mongodb

  • ops_manager
CWE
CWE-425

Direct Request ('Forced Browsing')