5 ms·
MongoDB 3.6, which was released in November 2016 defaults to listening on localhost only. A user must explicitly configure listening on a public IP address. ht
by jd_mongodb 5y ago
MongoDB 3.6, which was released in November 2016 defaults to listening on localhost only. A user must explicitly configure listening on a public IP address.
https://docs.mongodb.com/manual/release-notes/3.6-compatibility/#std-label-3.6-bind_ip-compatibility https://docs.mongodb.com/manual/release-notes/3.6-compatibil...
- robotmay 5y agoWhen running inside a docker container this won’t be much use though as the container handles the port forwarding. It would be a much better default to ensure authentication by default, considering how widespread exploiting of this has become with bots.
- kdmytro 5y agoYou don't have to bind to 0.0.0.0:[port]. If you want the server to remain accessible only locally, bind the container to 127.0.0.1:[port]. Docker is not preventing anyone from doing this.
- robotmay 5y agoYeah that's all fine and dandy, but the docker default is to bind to 0.0.0.0, so it really should be taken into account. I honestly would have to go and look up the flags needed to change the bind address, but I know the port ones (as I'm sure do many people who copy/paste docker lines from random repos), so it's still insecure for a common configuration/setup. I've never quite understood the opposition to just shipping mongodb with authentication on by default. What sort of use-case does it solve by not requiring it, and is it worth all the bad publicity every time this crops up in a new exploit report?