CVE-2016-6494 describes a vulnerability in MongoDB clients where .dbshell history files are created with world-readable permissions, potentially exposing sensitive information to local users. This medium-severity vulnerability (CVSS 5.5) has a low attack complexity and requires local access, but could lead to a high impact on confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.15CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | ||
>= 3.2, < 3.2.14CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.3.14CPE matchmatch criteria | cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:* | ||
25CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.