Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88030

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 8.3

Описание

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.

A flaw was found in the GridFS component of the MongoDB Ruby Driver. Improper neutralization of special elements in data query logic can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target, leading to data disclosure. Additionally, this flaw could allow an attacker to cause all GridFS file chunks in the affected bucket to be removed, resulting in a Denial of Service (DoS).

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8ruby:2.5/rubygem-mongoAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-917
https://bugzilla.redhat.com/show_bug.cgi?id=2531585rubygem-mongo: MongoDB Ruby Driver: Data disclosure and denial of service via query-operator injection

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
8 дней назад

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.

CVSS3: 8.3
nvd
8 дней назад

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.

CVSS3: 8.3
debian
8 дней назад

Improper neutralization of special elements in data query logic in the ...

CVSS3: 8.3
github
8 дней назад

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or cause all GridFS file chunks in the affected bucket to be removed, rendering stored file content unreadable.

8.3 High

CVSS3