Home
HIGH: 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NMEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
8.3.0 (custom) before 8.3.3
affected
8.2.0 (custom) before 8.2.10
affected
8.0.0 (custom) before 8.0.24
affected
7.0.0 (custom) before 7.0.35
affected
Description
A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields within the $vectorSearch stage filter expressions to be sent to the server as plaintext instead of ciphertext.
Problem types
CWE-319 Cleartext transmission of sensitive information
Product status
8.3.0 (custom) before 8.3.3
8.2.0 (custom) before 8.2.10
8.0.0 (custom) before 8.0.24
7.0.0 (custom) before 7.0.35
References
jira.mongodb.org/browse/SERVER-123507