The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
[
{
"id": "CVE-2016-6494-64ea98b7",
"signature_type": "Line",
"source": "https://github.com/mongodb/mongo/commit/035cf2afc04988b22cb67f4ebfd77e9b344cb6e0",
"target": {
"file": "src/mongo/shell/linenoise.cpp"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"38063034419634664737981663660779055012",
"101697571783015226221381688843369382507",
"185011636944525901495440648769089785365",
"70338109544889562649275598797745262164",
"155517756751757356375046794437329057913",
"332895618089064658357078612105625919264",
"262387501813905643580075955270225324243",
"42426834221099805833256320775712596191"
],
"threshold": 0.9
}
},
{
"id": "CVE-2016-6494-7bd88d64",
"signature_type": "Function",
"source": "https://github.com/mongodb/mongo/commit/035cf2afc04988b22cb67f4ebfd77e9b344cb6e0",
"target": {
"file": "src/mongo/shell/linenoise.cpp",
"function": "linenoiseHistorySave"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 291.0,
"function_hash": "60644063054288997552283925539806540792"
}
}
]