CVE Vulnerabilities

CVE-2019-2388

Direct Request ('Forced Browsing')

Published: May 13, 2020 | Modified: Jan 23, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1 version 4.1.5.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Ops_manager Mongodb 4.0.9 (including) 4.0.9 (including)
Ops_manager Mongodb 4.0.10 (including) 4.0.10 (including)
Ops_manager Mongodb 4.1.5 (including) 4.1.5 (including)

Potential Mitigations

References