arunbandari / mongo-gui

A web-based MongoDB graphical user interface
http://20.106.238.56:4321/
MIT License
280 stars 84 forks source link

Unauthorized Access Vulnerability in Default Configuration #123

Open tzf1003 opened 1 year ago

tzf1003 commented 1 year ago

Hello @arunbandari

I have identified a security vulnerability in the default configuration of your mongo-gui project. It currently does not have password protection enabled by default. As a result, assets associated with this project can be found on platforms such as FOFA and ZoomEye through ico searches. This exposes users' databases to potential data breaches.

For the security of users, I kindly advise that you modify the default configuration to enable password protection.

Thank you for your attention to this matter.

Best Regards, tzf1003