Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Warning From Lynis System Audit #43

Open
theklefti opened this issue Feb 22, 2022 · 0 comments
Open

Security Warning From Lynis System Audit #43

theklefti opened this issue Feb 22, 2022 · 0 comments

Comments

@theklefti
Copy link

theklefti commented Feb 22, 2022

Hi,

After installing Rocket.chat server via snap and running the lynis security audit on my server, I get the following warning with a link containing more info:

"MongoDB instance allows any user to access databases [DBS-1820]
https://cisofy.com/lynis/controls/DBS-1820/"

Details from the provided URL are:

Description
This control is displayed when no configured authorization mechanism was found on MongoDB.

How to solve
Usually the default permissions of MongoDB are restricted to the local machine and no authorization is needed. If the related MongoDB instance contains sensitive data, it means that without any form of authentication this data can be extracted. It is even more problematic when the instance is remotely available. During the last years this resulted in ransomware that keeps data in MongoDB instances hostage. Set the authorization setting to require authentication and define the authorization level (which user can access a particular database).

Is this secure? If anyone can suggest how to tighten up security here to remove this warning that would be much appreciated.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant