Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-6494

Опубликовано: 01 авг. 2016
Источник: redhat
CVSS3: 4
CVSS2: 2.1

Описание

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)mongodbWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)mongodbWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)mongodbWill not fix
Red Hat Enterprise MRG 2mongodbWill not fix
Red Hat OpenShift Enterprise 2mongodbWill not fix
Red Hat OpenStack Platform 8 (Liberty)mongodbWill not fix
Red Hat Satellite 6mongodbWill not fix
Red Hat Software Collectionsmongodb24-mongodbWill not fix
Red Hat Software Collectionsrh-mongodb26-mongodbWill not fix
Red Hat Software Collectionsrh-mongodb30upg-mongodbWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=1362553mongodb: world-readable .dbshell history file

4 Medium

CVSS3

2.1 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 10 лет назад

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.

CVSS3: 5.5
nvd
почти 10 лет назад

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.

CVSS3: 5.5
debian
почти 10 лет назад

The client in MongoDB uses world-readable permissions on .dbshell hist ...

CVSS3: 5.5
github
больше 4 лет назад

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.

4 Medium

CVSS3

2.1 Low

CVSS2