SV-265914r1028528_rule
V-265914
SRG-APP-000133-DB-000362
MD7X-00-003000
CAT II
10
Use the following commands to remove unauthorized access to a MongoDB database:
db.revokePrivilegesFromRole()
db.revokeRolesFromUser()
MongoDB commands for role management can be found here:
https://www.mongodb.com/docs/v7.0/reference/method/js-role-management/
Run the following command to get the roles from a MongoDB database.
For each database in MongoDB:
use <database>
db.getRoles(
{
rolesInfo: 1,
showPrivileges:true,
showBuiltinRoles: true
}
)
Run the following command to the roles assigned to users:
use admin
db.system.users.find()
Analyze the output and if any roles or users have unauthorized access, this is a finding. This will vary on an application basis.
V-265914
False
MD7X-00-003000
Run the following command to get the roles from a MongoDB database.
For each database in MongoDB:
use <database>
db.getRoles(
{
rolesInfo: 1,
showPrivileges:true,
showBuiltinRoles: true
}
)
Run the following command to the roles assigned to users:
use admin
db.system.users.find()
Analyze the output and if any roles or users have unauthorized access, this is a finding. This will vary on an application basis.
M
5637