6.1 Ensure that the HTTP status interface is disabled

Information

MongoDB by default provides an HTTP interface running on port 28017 to provide the home status page. This page provides certain critical information about the databases statistics and clients.

Please note that this function has been Deprecated since version 3.2.

Rationale:

An attacker could access the status page to learn more about the MongoDB server and determine how to compromise it.

Solution

Disable the HTTP status interface by setting nohttpinterface = True in the /etc/mongod.conf file.

Default Value:

Enabled

See Also

https://workbench.cisecurity.org/files/168

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b.

Plugin: Unix

Control ID: 2e013703520a04f1941b937091f5381a570e4dcd99974394cb20f4b81096f645