Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-20335
HistoryFeb 11, 2021 - 12:00 a.m.

CVE-2021-20335

2021-02-1100:00:00
ubuntu.com
ubuntu.com
10

CVSS2

4.1

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:A/AC:L/Au:S/C:P/I:P/A:N

CVSS3

6.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

AI Score

4.6

Confidence

High

EPSS

0

Percentile

12.6%

For MongoDB Ops Manager versions prior to and including 4.2.24 with
multiple OM application servers, that have SSL turned on for their MongoDB
processes, the upgrade to MongoDB Ops Manager versions prior to and
including 4.4.12 triggers a bug where Automation thinks SSL is being turned
off, and can disable SSL temporarily for members of the cluster. This issue
is temporary and eventually corrects itself after MongoDB Ops Manager
instances have finished upgrading to MongoDB Ops Manager 4.4. In addition,
customers must be running with clientCertificateMode=OPTIONAL /
allowConnectionsWithoutCertificates=true to be impacted*.* Customers
upgrading from Ops Manager 4.2.X to 4.2.24 and finally to Ops Manager
4.4.13+ are unaffected by this issue.

CVSS2

4.1

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:A/AC:L/Au:S/C:P/I:P/A:N

CVSS3

6.7

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

AI Score

4.6

Confidence

High

EPSS

0

Percentile

12.6%

Related for UB:CVE-2021-20335