Information disclosure in MongoDB - CVE-2016-6494
Published: October 3, 2016 / Updated: July 18, 2020
Vulnerability identifier: #VU31452
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6494
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to gain access to sensitive information.
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
Affected software
MongoDB
Guardium Data Security Center (GDSC)
Fedora
mongodb
Guardium Data Security Center (GDSC)
Fedora
mongodb
How to mitigate CVE-2016-6494
Install update from vendor's website.
MongoDB - update to 3.3.14
Guardium Data Security Center (GDSC) - update to 3.6.1
mongodb - addressed in versions 2.4.14-4.el6, 2.6.12-3.el7, 3.0.12-2.fc23, 3.2.8-2.fc24, 3.2.8-2.fc25
Guardium Data Security Center (GDSC) - update to 3.6.1
mongodb - addressed in versions 2.4.14-4.el6, 2.6.12-3.el7, 3.0.12-2.fc23, 3.2.8-2.fc24, 3.2.8-2.fc25
External References
- http://www.openwall.com/lists/oss-security/2016/07/29/4
- http://www.openwall.com/lists/oss-security/2016/07/29/8
- http://www.securityfocus.com/bid/92204
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832908
- https://bugzilla.redhat.com/show_bug.cgi?id=1362553
- https://github.com/mongodb/mongo/commit/035cf2afc04988b22cb67f4ebfd77e9b344cb6e0
- https://jira.mongodb.org/browse/SERVER-25335
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5MCE2ZLFBNOK3TTWSTXZJQGZVP4EEJDL/