The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
https://jira.mongodb.org/browse/SERVER-25335
https://github.com/mongodb/mongo/commit/035cf2afc04988b22cb67f4ebfd77e9b344cb6e0
https://bugzilla.redhat.com/show_bug.cgi?id=1362553
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832908
http://www.securityfocus.com/bid/92204