CVE-2016-6494
published 2016-10-03CVE-2016-6494: The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these…
PriorityP420medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.37%
29.6th percentile
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| mongodb | mongodb | < 3.0.15 | 3.0.15 |
| mongodb | mongodb | >= 0 < 1:2.4.9-1ubuntu2+esm2 | 1:2.4.9-1ubuntu2+esm2 |
| mongodb | mongodb | >= 0 < 1:2.6.10-0ubuntu1+esm2 | 1:2.6.10-0ubuntu1+esm2 |
| mongodb | mongodb | >= 0 < 1:3.6.3-0ubuntu1.4+esm1 | 1:3.6.3-0ubuntu1.4+esm1 |
| mongodb | mongodb | >= 3.2 < 3.2.14 | 3.2.14 |
| mongodb | mongodb | >= 3.3 < 3.3.14 | 3.3.14 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MongoDB vulnerabilities
vendor_ubuntu·2026-02-25·CVSS 5.0
CVE-2018-20802 [MEDIUM] MongoDB vulnerabilities
Title: MongoDB vulnerabilities
Summary: Several security issues were fixed in MongoDB.
Eliot Horowitz discovered that MongoDB may fail to validate some instances
of malformed BSON. A remote attacker could possibly use this issue to cause
MongoDB to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2015-1609)
It was discovered that MongoDB read raw permissions from .dbshell history
files. A local attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04
LTS. (CVE-2016-6494)
Travis Brown discovered that MongoDB may be unable to parse specially
crafted UTF-8 strings in BSON requests. A remote attacker could possibly
use this issue to cause MongoDB to crash, resulting in a denial
Red Hat
mongodb: world-readable .dbshell history file
vendor_redhat·2016-08-01·CVSS 5.5
CVE-2016-6494 [MEDIUM] CWE-732 mongodb: world-readable .dbshell history file
mongodb: world-readable .dbshell history file
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
Package: mongodb (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Will not fix
Package: mongodb (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Will not fix
Package: mongodb (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Will not fix
Package: mongodb (Red Hat Enterprise MRG 2) - Will not fix
Package: mongodb (Red Hat OpenShift Enterprise 2) - Will not fix
Package: mongodb (Red Hat OpenStack Platform 8 (Liberty)) - Will not fix
Package: mongodb (Red Hat Satellite 6) - Will not fix
Package: mongodb24-mongodb (Red Hat Software Collections) - Wi
OSV
mongodb vulnerabilities
osv·2026-02-25·CVSS 5.0
CVE-2015-1609 [MEDIUM] mongodb vulnerabilities
mongodb vulnerabilities
Eliot Horowitz discovered that MongoDB may fail to validate some instances
of malformed BSON. A remote attacker could possibly use this issue to cause
MongoDB to crash, resulting in a denial of service. This issue only
affected Ubuntu 14.04 LTS. (CVE-2015-1609)
It was discovered that MongoDB read raw permissions from .dbshell history
files. A local attacker could possibly use this issue to obtain sensitive
information. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04
LTS. (CVE-2016-6494)
Travis Brown discovered that MongoDB may be unable to parse specially
crafted UTF-8 strings in BSON requests. A remote attacker could possibly
use this issue to cause MongoDB to crash, resulting in a denial of service.
This issue only affected Ubuntu 18.04 LTS. (CVE-201
GHSA
GHSA-j4pw-hgvj-fq4w: The client in MongoDB uses world-readable permissions on
ghsa_unreviewed·2022-05-17
CVE-2016-6494 [MEDIUM] CWE-200 GHSA-j4pw-hgvj-fq4w: The client in MongoDB uses world-readable permissions on
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
OSV
CVE-2016-6494: The client in MongoDB uses world-readable permissions on
osv·2016-10-03·CVSS 5.5
CVE-2016-6494 [MEDIUM] CVE-2016-6494: The client in MongoDB uses world-readable permissions on
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-6494 mongodb: world-readable .dbshell history file [epel-all]
bugzilla·2016-08-02·CVSS 5.5
CVE-2016-6494 [MEDIUM] CVE-2016-6494 mongodb: world-readable .dbshell history file [epel-all]
CVE-2016-6494 mongodb: world-readable .dbshell history file [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
CVE-2016-6494 mongodb: world-readable .dbshell history file
bugzilla·2016-08-02·CVSS 5.5
CVE-2016-6494 [MEDIUM] CVE-2016-6494 mongodb: world-readable .dbshell history file
CVE-2016-6494 mongodb: world-readable .dbshell history file
It was found that MongoDB creates a world-readable .dbshell history file in a user's directory:
The mongodb client doesn't store authentication commands, but there's still information leakage, though, even if only about database and collection names, or data structure.
As for data itself, the history could also contain sensitive information; for instance, if usernames for some other service were stored in a mongo collection, the history could contain lines like:
db.users.find({user:"foo"})
or even:
db.users.update({user:"foo"},{$set:{password:"OhComeOnNow"}})
Upstream bug (closed as "Works as Designed"):
https://jira.mongodb.org/browse/SERVER-25335
CVE request:
http://seclists.org/oss-sec/2016/q3/199
Discussion:
Create
Bugzilla
CVE-2016-6494 mongodb: world-readable .dbshell history file [fedora-all]
bugzilla·2016-08-02·CVSS 5.5
CVE-2016-6494 [MEDIUM] CVE-2016-6494 mongodb: world-readable .dbshell history file [fedora-all]
CVE-2016-6494 mongodb: world-readable .dbshell history file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
http://www.openwall.com/lists/oss-security/2016/07/29/4http://www.openwall.com/lists/oss-security/2016/07/29/8http://www.securityfocus.com/bid/92204https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832908https://bugzilla.redhat.com/show_bug.cgi?id=1362553https://github.com/mongodb/mongo/commit/035cf2afc04988b22cb67f4ebfd77e9b344cb6e0https://jira.mongodb.org/browse/SERVER-25335https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5MCE2ZLFBNOK3TTWSTXZJQGZVP4EEJDL/http://www.openwall.com/lists/oss-security/2016/07/29/4http://www.openwall.com/lists/oss-security/2016/07/29/8http://www.securityfocus.com/bid/92204https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832908https://bugzilla.redhat.com/show_bug.cgi?id=1362553https://github.com/mongodb/mongo/commit/035cf2afc04988b22cb67f4ebfd77e9b344cb6e0https://jira.mongodb.org/browse/SERVER-25335https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5MCE2ZLFBNOK3TTWSTXZJQGZVP4EEJDL/
2016-10-03
Published