First published: Mon Jan 25 2016(Updated: )
Jan Hutař of Red Hat reports: MongoDB on Satellite 6 is configured without a password by default, this allows local users to connect to MongoDB and cause information to be deleted.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Satellite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1301703 is critical due to the potential for unauthorized local access and data deletion.
To fix REDHAT-BUG-1301703, configure MongoDB with a strong password and restrict access appropriately.
Any installation of Red Hat Satellite 6 that is using MongoDB without password protection is affected by REDHAT-BUG-1301703.
The default configuration issue in REDHAT-BUG-1301703 is that MongoDB is set up without a password, allowing local users to connect freely.
The potential risks of REDHAT-BUG-1301703 include unauthorized data access, modification, or deletion by local users.