6.4 Ensure that server-side scripting is disabled if not needed

Information

MongoDB supports the execution of JavaScript code for certain server-side operations: mapReduce, group, and $where. If you do not use these operations, server-side scripting should be disabled.
Rationale:
If server-side scripting is not needed and is not disabled, this introduces unnecessary risk that an attacker may take advantage of insecure coding.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

If server-side scripting is not required, disable it by using the --noscripting option on the command line.
Default Value:
Enabled

See Also

https://workbench.cisecurity.org/files/1705

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|18.9

Plugin: Windows

Control ID: e2cea971305830fdd57dd6d1e4c3dbbc1b4230726035155639170b90e9cb173f