MongoDB 3.6, which was released in November 2016 defaults to listening on localhost only. A user must explicitly configure listening on a public IP address.
https://docs.mongodb.com/manual/release-notes/3.6-compatibil...
https://docs.mongodb.com/manual/release-notes/3.6-compatibil...
I've never quite understood the opposition to just shipping mongodb with authentication on by default. What sort of use-case does it solve by not requiring it, and is it worth all the bad publicity every time this crops up in a new exploit report?