CVEs Blog | G5 Cyber Security

CVE-2016-6494 – The client in MongoDB uses world-readable permissions on .dbshell history

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6494

Reference (s):

Exit mobile version