SV-96613r1_rule
V-81899
SRG-APP-000328-DB-000301
MD3X-00-000570
CAT II
10
Revoke any roles with unnecessary privileges to privileged functionality by executing the revoke command as documented here:
https://docs.mongodb.com/v3.4/reference/method/db.revokeRolesFromUser/
Revoke any unnecessary privileges from any roles by executing the revoke command as document here:
https://docs.mongodb.com/v3.4/reference/method/db.revokePrivilegesFromRole/
If a new role with associated privileges needs to be created, follow the documentation here:
https://docs.mongodb.com/v3.4/reference/command/createRole/
Review the system documentation to obtain the definition of the database/DBMS functionality considered privileged in the context of the system in question.
If any functionality considered privileged has access privileges granted to non-privileged users, this is a finding.
V-81899
False
MD3X-00-000570
Review the system documentation to obtain the definition of the database/DBMS functionality considered privileged in the context of the system in question.
If any functionality considered privileged has access privileges granted to non-privileged users, this is a finding.
M
3265