The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
| Software | From | Fixed in |
|---|---|---|
mongodb / mongodb
|
3.2 | 3.2.14 |
mongodb / mongodb
|
3.3 | 3.3.14 |
mongodb / mongodb
|
- | 3.0.15 |
| fedoraproject / fedora | 25 | 25.x |