Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4fx2-v6gr-hm23

Опубликовано: 22 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

EPSS

Процентиль: 8%
0.00188
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-441

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

CVSS3: 6.5
nvd
около 1 месяца назад

An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This can result in corruption of encrypted query correctness.

CVSS3: 6.5
debian
около 1 месяца назад

An authenticated user with write privileges on a Queryable Encryption- ...

EPSS

Процентиль: 8%
0.00188
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-441