SV-265913r1028525_rule
V-265913
SRG-APP-000133-DB-000200
MD7X-00-002900
CAT II
10
For each user identified as having a "dbOwner" role on a database they are not authorized for, revoke the "dbOwner" role from that user on that database by running the following commands:
use <database>
db.revokeRolesFromUser() command
https://www.mongodb.com/docs/v7.0/reference/command/revokeRolesFromUser/
Example to revoke "dbOwner" role from "user1" on the "anotherDatabase" in the "admin" database:
use admin
db.revokeRolesFromUser(
"user1",
[
{ role: "dbOwner", db: "anotherDatabase" }
]
)
For each database in MongoDB, run the following commands:
use <database>
db.getUsers()
Example output:
{
_id: 'admin.user1',
userId: UUID('b78e490a-4661-491f-8197-c3251934e785'),
user: 'user1',
db: 'admin',
roles: [
{ role: 'readWrite', db: 'myDatabase' },
{ role: 'dbOwner', db: 'myDatabase' },
{ role: 'dbOwner', db: 'anotherDatabase' }
]
Here, the user named "user1" in the "admin" database has a role of "dbOwner" for the database (db:) "myDatabase" and the database (db:) "anotherDatabase".
For users where the role of "dbOwner" is found, verify with the organization or site-specific documentation whether the user is authorized for the "dbOwner" role on the database resources listed.
If the user account has the role of "dbOwner" but is not authorized for the role for any database listed in their output, this is a finding.
V-265913
False
MD7X-00-002900
For each database in MongoDB, run the following commands:
use <database>
db.getUsers()
Example output:
{
_id: 'admin.user1',
userId: UUID('b78e490a-4661-491f-8197-c3251934e785'),
user: 'user1',
db: 'admin',
roles: [
{ role: 'readWrite', db: 'myDatabase' },
{ role: 'dbOwner', db: 'myDatabase' },
{ role: 'dbOwner', db: 'anotherDatabase' }
]
Here, the user named "user1" in the "admin" database has a role of "dbOwner" for the database (db:) "myDatabase" and the database (db:) "anotherDatabase".
For users where the role of "dbOwner" is found, verify with the organization or site-specific documentation whether the user is authorized for the "dbOwner" role on the database resources listed.
If the user account has the role of "dbOwner" but is not authorized for the role for any database listed in their output, this is a finding.
M
5637