The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
References
Configurations
History
No history.
Information
Published : 2016-10-03 18:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-6494
Mitre link : CVE-2016-6494
CVE.ORG link : CVE-2016-6494
JSON object : View
Products Affected
mongodb
- mongodb
fedoraproject
- fedora
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor