Impact
The MongoDB Ruby Driver’s GridFS component fails to neutralize special elements in a caller‑supplied structured file identifier, allowing the identifier to be interpreted as a query condition instead of a literal. This query‑operator injection, classified as CWE‑917 and CWE‑943, lets an authenticated user read file content beyond the intended target or delete all chunks of a GridFS bucket, resulting in data disclosure and denial of service.
Affected Systems
The vulnerability affects the MongoDB Ruby Driver. No specific version ranges are listed, so any installed version of the driver should be assumed at risk until an updated package that resolves the injection flaw is deployed.
Risk and Exploitability
With a CVSS score of 6.1, the risk is moderate. The EPSS score of 0.00259 indicates an extremely low but nonzero probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to control or influence a file identifier supplied to the driver, typically through an authenticated application component. No additional network exposure beyond normal driver usage is required for exploitation.
OpenCVE Enrichment