Impact
Improper neutralization of special elements in GridFS query logic inside the MongoDB C++ Driver allows an authenticated caller to supply a structured file identifier that is interpreted as a query condition rather than a literal value. This flaw can lead to two significant impacts: an attacker can read content from files beyond the intended target, thereby disclosing sensitive data, or cause all GridFS file chunks in the affected bucket to be removed, resulting disabling subsequent read operations. Both outcomes compromise confidentiality and availability.
Affected Systems
This vulnerability affects applications that use the MongoDB C++ Driver to work with GridFS. No specific driver versions are listed in the advisory, so any installation of the driver that includes the vulnerable GridFS component remains at risk.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so the precise exploitation likelihood is uncertain. The likely attack vector is an authenticated user or application component that can influence the file identifier passed to the driver; from that position an attacker could inject query operators to read or delete data. Without patching or mitigating input handling, the potential for unauthorized data exposure or bucket data loss remains significant.
OpenCVE Enrichment