Impact
The MongoDB Go Driver contains a flaw in its GridFS component identifier that is interpreted as a query condition instead of a literal identifier. This improper neutralization allows the attacker to delete all GridFS file chunks within a bucket, effectively erasing stored data. The weakness is categorized as CWE-1287 and CWE-943, reflecting improper neutralization of special elements in query logic.
Affected Systems
The vulnerability affects applications that use the MongoDB Go Driver. No specific driver versions are listed in the known data, so impacted.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity risk. The EPSS score of < 1% shows a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated user with the ability to influence the file identifier passed to the driver. While the exact application context is not specified, it is inferred that the threat vector is through controlled input to an authenticated credentials or exploit another vulnerability to gain that capability.
OpenCVE Enrichment