The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade pymongo to version 4.18.1 or higher.
Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Data Query Logic using NoSQL operators in the GridFS file identifier handling in gridfs/synchronous/grid_file.py, gridfs/asynchronous/grid_file.py, and gridfs/grid_file_shared.py, where delete(), rename(), find_one(), exists(), abort(), and the chunk cursor build their filters as {"_id": file_id} and {"files_id": file_id} with the caller's value placed directly as the match value. An attacker can delete, rename, or read files other than the one addressed, up to every file in the bucket, by supplying a mapping such as {"$gt": ""} or {"$ne": null} in place of an identifier, which the server evaluates as an operator expression rather than as a value to match. This requires the application to pass a value it received from the user into one of these methods without coercing it to an ObjectId or other scalar first, which is the usual shape when a file identifier arrives in a decoded JSON request body.