Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1362553 - (CVE-2016-6494) CVE-2016-6494 mongodb: world-readable .dbshell history file
CVE-2016-6494 mongodb: world-readable .dbshell history file
Status: CLOSED WONTFIX
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20160801,reported=2...
: Security
Depends On: 1362554 1362555
Blocks:
  Show dependency treegraph
 
Reported: 2016-08-02 09:39 EDT by Martin Prpič
Modified: 2016-09-27 04:46 EDT (History)
62 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-08-02 09:41:50 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Martin Prpič 2016-08-02 09:39:02 EDT
It was found that MongoDB creates a world-readable .dbshell history file in a user's directory:

The mongodb client doesn't store authentication commands, but there's still information leakage, though, even if only about database and collection names, or data structure.

As for data itself, the history could also contain sensitive information; for instance, if usernames for some other service were stored in a mongo collection, the history could contain lines like:

  db.users.find({user:"foo"})

or even:

  db.users.update({user:"foo"},{$set:{password:"OhComeOnNow"}})

Upstream bug (closed as "Works as Designed"):

https://jira.mongodb.org/browse/SERVER-25335

CVE request:

http://seclists.org/oss-sec/2016/q3/199
Comment 1 Martin Prpič 2016-08-02 09:40:47 EDT
Created mongodb tracking bugs for this issue:

Affects: fedora-all [bug 1362554]
Affects: epel-all [bug 1362555]
Comment 2 Marek Skalický 2016-08-02 10:18:37 EDT
So should be Fedora and EPEL bugs fixed if this bug is closed as WONTFIX?
Comment 3 Martin Prpič 2016-08-02 10:33:50 EDT
(In reply to Marek Skalický from comment #2)
> So should be Fedora and EPEL bugs fixed if this bug is closed as WONTFIX?

I'll leave that decision to the Fedora/EPEL maintaner but seeing as this was closed upstream, and home directories in RHEL and Fedora are not world readable to other users, I don't see this as something worth developing an out-of-band patch for.
Comment 4 Pavel Raiskup 2016-09-27 02:15:25 EDT
FWIW, this seems to be fixed upstream in the end, in link from comment #0.
Comment 5 Marek Skalický 2016-09-27 04:46:27 EDT
Fedora/EPEL bugs are already fixed/in testing.

Note You need to log in before you can comment on or make changes to this bug.