Impact
A flaw in the encryption configuration generator of the Mongoid object‑document mapper can lead to fields that are intended for client‑side field‑level encryption being persisted in cleartext. The bug causes unresolved database names in the encryption schema map, and no error or warning is emitted. As a result, data that was expected to be protected ends up stored unencrypted, allowing an unauthorized party to read it later.
Affected Systems
The vulnerability affects Mongoid, the ODM provided by MongoDB Inc. No specific product versions were listed in the advisory, so any release that includes the described encryption configuration mechanism may be at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1% suggests that, in practice, exploitation is unlikely, and the flaw is not currently listed in the CISA KEV catalog. Nevertheless, an attacker with ordinary read access to the database can retrieve sensitive data that was meant to be encrypted, leading to unintended disclosure. The attack vector is inferred to be an internal or privileged user who gains read access to the database, since no network or remote execution path is described.
OpenCVE Enrichment