Impact
The vulnerability, identified as CWE‑94 and CWE‑943, arises from improper neutralization of special elements in the GridFS component of the MongoDB Java Driver. The driver treats a caller‑supplied structured file identifier as a query condition rather than a literal, allowing an authenticated user who can influence that identifier to read any stored file, delete all GridFS file chunks in a bucket, or rename a file other than the intended target. The resulting impact includes unauthorized data disclosure and destructive deletion of files.
Affected Systems
The flaw affects applications that use the MongoDB Java Driver, specifically its GridFS component. No specific driver version numbers are listed in the CVE, so any deployment using the Java Driver prior to the fix is potentially vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 6.1, which is classified as medium severity. The EPSS score is 0.00253, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who can supply or influence the file identifier; once a malicious query is injected, the attacker can obtain arbitrary file content or wipe a bucket via deletion or renaming. The likely attack vector is via application interfaces that accept arbitrary identifiers, so the risk is moderate but significant for applications exposing file retrieval or management functionality.
OpenCVE Enrichment