Описание
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
EPSS
Процентиль: 27%
0.00337
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-470
Связанные уязвимости
CVSS3: 9.8
github
3 дня назад
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
EPSS
Процентиль: 27%
0.00337
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-470