Impact
Mongoid contains an unsafe reflection weakness in its document persistence layer. Keys supplied by an unauthenticated party can be passed through the embedding application and cause internal method invocation instead of the intended array field update. This flaw can result in unintended removal of stored records and can make the embedding application become unresponsive as a denial‑of‑service condition.
Affected Systems
The vulnerability affects Mongoid, MongoDB Inc.'s object‑document mapping library. No specific version information is provided in the advisory, so any deployment of Mongoid that does not guard against unvalidated input may be affected. Applications that embed Mongoid without proper input validation are at risk.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. The EPSS score of less than 1 % suggests that, while exploit attempts are unlikely at present, the probability is non‑zero. The issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated user sending crafted input to the application layer, which forwards the data to Mongoid. By doing so, an attacker can delete arbitrary documents and trigger a crash or denial of service without needing privileged database access.
OpenCVE Enrichment