Potential exposure of log information in Ops Manager
CVE-2019-2388

5.8MEDIUM

Key Information:

Vendor
MongoDB
Vendor
CVE Published:
13 May 2020

Summary

In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1 version 4.1.5.

Affected Version(s)

MongoDB Ops Manager 4.0.9

MongoDB Ops Manager 4.0.10

MongoDB Ops Manager 4.1.5

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.