CVE-2016-6494: Fedoraproject Fedora

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.

Affected products

  • Fedoraproject Fedora: version 25 only
  • MongoDB MongoDB: before 3.0.15 (fixed in 3.0.15); from 3.2, before 3.2.14 (fixed in 3.2.14); from 3.3, before 3.3.14 (fixed in 3.3.14)

Published 2016-10-03. Last modified 2026-06-17.