Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f96f-54rq-c385

Опубликовано: 11 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.

EPSS

Процентиль: 19%
0.00264
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-807

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.

CVSS3: 6.5
nvd
около 1 месяца назад

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.

CVSS3: 6.5
debian
около 1 месяца назад

An issue in MongoDB Server's Atlas Vector Search feature could allow a ...

EPSS

Процентиль: 19%
0.00264
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-807