Impact
An authentication-aware injection flaw in the GridFS component of the MongoDB C# Driver allows an attacker who can influence a structured file identifier to cause the driver to treat that identifier as a query expression instead of a literal file name. The result is that the attacker can read the contents of files that were not intended to be exposed, delete all data chunks in a bucket, or rename a file that is unrelated to the target. This breach of confidentiality is coupled with a potential loss of integrity and availability of the stored data.
Affected Systems
The issue affects applications that use the MongoDB C# Driver, specifically those that interact with GridFS. The driver is part of the MongoDB official .NET driver package. No specific driver version is listed in the data, so any deployments using the driver should review their version and verify if it contains the fix.
Risk and Exploitability
The vulnerability has a CVSS score of 6.1, indicating a moderate severity. No EPSS score is currently available. The flaw is not listed in CISA’s KEV catalog, indicating there have been no known large‑scale exploitation incidents reported so far. Given that the flaw requires the attacker to influence an authenticated file identifier, the attack vector is likely an application‑level user or a higher‑privilege system component, rather than a remote network exploit. The impact could be significant for applications that rely on GridFS for storing sensitive or critical data.
OpenCVE Enrichment