In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance. This issue affects: MongoDB Inc. MongoDB Ops Manager 4.0 versions 4.0.9, 4.0.10 and MongoDB Ops Manager 4.1 version 4.1.5.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ops_manager | Mongodb | 4.0.9 (including) | 4.0.9 (including) |
Ops_manager | Mongodb | 4.0.10 (including) | 4.0.10 (including) |
Ops_manager | Mongodb | 4.1.5 (including) | 4.1.5 (including) |