Impact
Mongoid creates client‑side field‑level encryption schemas. When embedded models declare encrypted fields, the encryption rules can be skipped, causing those fields to be stored as plaintext. The vulnerability allows the intended confidentiality of data to be completely lost, potentially exposing sensitive information.
Affected Systems
Mongoid, a Ruby ODM library for MongoDB provided by MongoDB Inc. The issue affects any application that uses Mongoid's client‑side field‑level encryption and relies on embedded models for encrypted fields. No exact version range is reported, so all installations using this feature should be considered vulnerable.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability is moderate to high severity. The EPSS score is under 1%, suggesting a low likelihood of active exploitation at the time of analysis, and it is not listed in the CISA KEV catalog. Nonetheless, the missing encryption is straightforward to detect by reading database documents, backup files, or raw data files, so the primary attack vector is an attacker with routine database read privileges or access to backups.
OpenCVE Enrichment