Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-30997

mongo cli --password is masked, but not when using mongodb:// connection string

    • Fully Compatible
    • v4.0, v3.6, v3.4
    • Platforms 2018-07-30
    • 0

      When using the following:

      $ mongo --host --user admin --password superSecret12345
      $ ps auxww | grep mongo
      $ mongo mongodb://admin:superSecret12345@
      $ ps auxww | grep mongo

      You see that --password value has been masked with "x" characters, so you don't easily expose the password to others. However, when connecting using the mongodb:// connection string, which is still waiting to be documented ( DOCS-9033 ) , the password is not masked.

      In the mongodb:// method as well, the password is also leaked into the stdout of the cli when it displays "connecting to: mongodb://admin:superSecret12345@"

      I believe these should be masked in the same way, so the password is never displayed in the running process cmdline or in the stdout line displayed saying it is connecting.

            jonathan.reams@mongodb.com Jonathan Reams
            aqueen Aaron Queen
            0 Vote for this issue
            10 Start watching this issue