Information disclosure in MongoDB - CVE-2016-6494

 

Information disclosure in MongoDB - CVE-2016-6494

Published: October 3, 2016 / Updated: July 18, 2020


Vulnerability identifier: #VU31452
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6494
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.


Affected software

MongoDB
Guardium Data Security Center (GDSC)
Fedora
mongodb

How to mitigate CVE-2016-6494

Install update from vendor's website.

MongoDB - update to 3.3.14
Guardium Data Security Center (GDSC) - update to 3.6.1
mongodb - addressed in versions 2.4.14-4.el6, 2.6.12-3.el7, 3.0.12-2.fc23, 3.2.8-2.fc24, 3.2.8-2.fc25

External References

Related Security Bulletins