Impact
The defect in the MongoDB Entity Framework Core Provider allows a malformed connection string that includes a database name to unintentionally turn off field level encryption. As a result, data stored and retrieved through that provider may be persisted in plain form, exposing sensitive information to anyone with access to the database. The weakness is an improper handling of sensitive information (CWE-311).
Affected Systems
Applications that rely on MongoDB Inc.'s Entity Framework Core Provider and embed a database name in their connection string are affected. No specific version range is listed, so any edition of the provider that includes the vulnerability is at risk.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not in the CISA Known Exploited Vulnerabilities catalog, reducing the likelihood of public exploitation. The most plausible attack vector is misconfiguration or tampering with the connection string by insiders or compromised application code, which can lead to unencrypted data storage without any additional privileges.
OpenCVE Enrichment