Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp8p-fq38-v738

Опубликовано: 10 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.

EPSS

Процентиль: 1%
0.00103
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.

CVSS3: 6.5
nvd
около 2 месяцев назад

A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.

CVSS3: 6.5
debian
около 2 месяцев назад

A bug in query analysis processing of the $vectorSearch aggregation st ...

EPSS

Процентиль: 1%
0.00103
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-319