SV-96605r1_rule
V-81891
SRG-APP-000251-DB-000391
MD3X-00-000500
CAT II
10
Disable the "javascriptEnabled" option.
Edit the MongoDB configuration file (default location: /etc/mongod.conf" to include the following:
security:
javascriptEnabled: false
MongoDB operations permit arbitrary JavaScript expressions to be run directly on the server.
If the following parameter is not present or not set as show below in the MongoDB configuration file (default location: /etc/mongod.conf), this is a finding.
security:
javascriptEnabled: "false"
V-81891
False
MD3X-00-000500
MongoDB operations permit arbitrary JavaScript expressions to be run directly on the server.
If the following parameter is not present or not set as show below in the MongoDB configuration file (default location: /etc/mongod.conf), this is a finding.
security:
javascriptEnabled: "false"
M
3265