Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20335

Опубликовано: 11 фев. 2021
Источник: nvd
CVSS3: 6.7
CVSS3: 4.6
CVSS2: 4.1
EPSS Низкий

Описание

For MongoDB Ops Manager versions prior to and including 4.2.24 with multiple OM application servers, that have SSL turned on for their MongoDB processes, the upgrade to MongoDB Ops Manager versions prior to and including 4.4.12 triggers a bug where Automation thinks SSL is being turned off, and can disable SSL temporarily for members of the cluster. This issue is temporary and eventually corrects itself after MongoDB Ops Manager instances have finished upgrading to MongoDB Ops Manager 4.4. In addition, customers must be running with clientCertificateMode=OPTIONAL / allowConnectionsWithoutCertificates=true to be impacted*.* Customers upgrading from Ops Manager 4.2.X to 4.2.24 and finally to Ops Manager 4.4.13+ are unaffected by this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mongodb:ops_manager:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 4.2.24 (включая)

EPSS

Процентиль: 18%
0.00056
Низкий

6.7 Medium

CVSS3

4.6 Medium

CVSS3

4.1 Medium

CVSS2

Дефекты

CWE-319
CWE-319

Связанные уязвимости

CVSS3: 6.7
ubuntu
почти 5 лет назад

For MongoDB Ops Manager versions prior to and including 4.2.24 with multiple OM application servers, that have SSL turned on for their MongoDB processes, the upgrade to MongoDB Ops Manager versions prior to and including 4.4.12 triggers a bug where Automation thinks SSL is being turned off, and can disable SSL temporarily for members of the cluster. This issue is temporary and eventually corrects itself after MongoDB Ops Manager instances have finished upgrading to MongoDB Ops Manager 4.4. In addition, customers must be running with clientCertificateMode=OPTIONAL / allowConnectionsWithoutCertificates=true to be impacted*.* Customers upgrading from Ops Manager 4.2.X to 4.2.24 and finally to Ops Manager 4.4.13+ are unaffected by this issue.

CVSS3: 4.6
github
больше 3 лет назад

For MongoDB Ops Manager 4.2.X with multiple OM application servers, that have SSL turned on for their MongoDB processes, the upgrade to MongoDB Ops Manager 4.4.X triggers a bug where Automation thinks SSL is being turned off, and can disable SSL temporarily for members of the cluster. This issue is temporary and eventually corrects itself after MongoDB Ops Manager instances have finished upgrading to MongoDB Ops Manager 4.4. In addition, customers must be running with clientCertificateMode=OPTIONAL / allowConnectionsWithoutCertificates=true to be impacted.

EPSS

Процентиль: 18%
0.00056
Низкий

6.7 Medium

CVSS3

4.6 Medium

CVSS3

4.1 Medium

CVSS2

Дефекты

CWE-319
CWE-319