SV-279342r1179447_rule
V-279342
SRG-APP-000133-DB-000362
MD8X-00-002800
CAT II
10
Use the following commands to remove unauthorized access to a MongoDB database:
db.revokePrivilegesFromRole()
db.revokeRolesFromUser()
MongoDB commands for role management can be found here:
https://www.mongodb.com/docs/v8.0/reference/method/js-role-management/
For each database in MongoDB, run the following command to obtain the roles:
use <database>
db.getRoles(
{
rolesInfo: 1,
showPrivileges:true,
showBuiltinRoles: true
}
)
Run the following command to the roles assigned to users:
use admin
db.system.users.find()
Analyze the output and if any roles or users have unauthorized access, this is a finding. This will vary on an application basis.
V-279342
False
MD8X-00-002800
For each database in MongoDB, run the following command to obtain the roles:
use <database>
db.getRoles(
{
rolesInfo: 1,
showPrivileges:true,
showBuiltinRoles: true
}
)
Run the following command to the roles assigned to users:
use admin
db.system.users.find()
Analyze the output and if any roles or users have unauthorized access, this is a finding. This will vary on an application basis.
M
5728