Run MongoDB with Secure Configuration Options - config - 'enableLocalhostAuthBypass = 0'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

enableLocalhostAuthBypass controls whether localhost authentication can be bypassed.

Solution

Set enableLocalhostAuthBypass to 0

See Also

http://docs.mongodb.org/manual/administration/security-checklist/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 78e7073a668c220fd9f809495c867257e211499c14188f6c04ebad77be17f38f