RSS   Vulnerabilities for 'Ops manager'   RSS

2021-02-11
 
CVE-2021-20335

CWE-319
 

 
For MongoDB Ops Manager 4.2.X with multiple OM application servers, that have SSL turned on for their MongoDB processes, the upgrade to MongoDB Ops Manager 4.4.X triggers a bug where Automation thinks SSL is being turned off, and can disable SSL temporarily for members of the cluster. This issue is temporary and eventually corrects itself after MongoDB Ops Manager instances have finished upgrading to MongoDB Ops Manager 4.4. In addition, customers must be running with clientCertificateMode=OPTIONAL / allowConnectionsWithoutCertificates=true to be impacted.

 
2020-05-13
 
CVE-2019-2388

CWE-425
 

 
In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1 version 4.1.5.

 

 >>> Vendor: Mongodb 10 Products
Mongodb
BSON
Libbson
Js-bson
Mongodb enterprise kubernetes operator
C driver
Ops manager
Libmongocrypt
Java driver
Rust driver


Copyright 2024, cxsecurity.com

 

Back to Top