The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6494
Reference (s):
- BID:92204
- URL: http://www.securityfocus.com/bid/92204
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832908
- https://bugzilla.redhat.com/show_bug.cgi?id=1362553
- https://github.com/mongodb/mongo/commit/035cf2afc04988b22cb67f4ebfd77e9b344cb6e0

