Impact
Applications using the MongoDB Entity Framework Core Provider can experience unintended disabling of TLS and schema‑map enforcement when independent encryption settings are combined with provider settings, causing protected fields to be stored unencrypted and exposing sensitive data; the flaw arises from improper handling of configuration, leading to confidentiality loss.
Affected Systems
MongoDB Entity Framework Core Provider used in .NET applications, with no specific vendor version disclosed, meaning any installation that merges independent encryption settings with provider defaults is potentially affected.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate threat; the EPSS score of "< 1%" points to a low likelihood of current exploitation; the vulnerability is not listed in the CISA KEV catalog. An attacker would need to influence application configuration or merge logic, limiting the attack surface and making the risk moderate but potentially critical if such access is obtained.
OpenCVE Enrichment