-
Type: Bug
-
Resolution: Done
-
Priority: Major - P3
-
None
-
Affects Version/s: None
-
Component/s: Security
-
None
-
ALL
-
I have two users on Mongo DB 3.2.7, a user with root role and another user with read only role on the database. When I login as root then switch to read only user without exiting the shell, MongoDB allows me to run and execute root level commands even though I am logged in as the read only user. To reproduce the problem do the following.
I logged in as the user with root access using
use admin
db.auth("rootUser","Password")
run commands like show databases, show collections everything works find.
Then without exiting the shell, I now logged in as the read only user
use dbabc
db.auth("readOnlyUser","Password")
Now logged in as this user, I can drop, list db and perform all other root operation. I think this is very dangerous. I tried to reproduce the problem several times and it works.
The only time the read only user works as expected is when I exit the shell then login again as the read only user. See the execution of commands below.