Run MongoDB with Secure Configuration Options - config - 'setParameter enableLocalhostAuthBypass = 0'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

enableLocalhostAuthBypass controls whether localhost authentication can be bypassed.

Solution

Set enableLocalhostAuthBypass to 0

See Also

http://docs.mongodb.org/manual/administration/security-checklist/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 4b58473a1e700275aec65d2a51c5c816c4bfed83a7a3cf291140d0efa9769420