The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
{ "binaries": [ { "binary_version": "1:3.6.3-0ubuntu1", "binary_name": "mongodb" }, { "binary_version": "1:3.6.3-0ubuntu1", "binary_name": "mongodb-clients" }, { "binary_version": "1:3.6.3-0ubuntu1", "binary_name": "mongodb-clients-dbgsym" }, { "binary_version": "1:3.6.3-0ubuntu1", "binary_name": "mongodb-server" }, { "binary_version": "1:3.6.3-0ubuntu1", "binary_name": "mongodb-server-core" }, { "binary_version": "1:3.6.3-0ubuntu1", "binary_name": "mongodb-server-core-dbgsym" } ], "ubuntu_priority": "low", "availability": "No subscription required" }