CyberRota Analysis
AI-GeneratedMongoDB Server is vulnerable due to improper validation of request parameters during Queryable Encryption maintenance operations, which can be exploited by authenticated users with readWrite privileges. This flaw may lead to server crashes or excessive internal writes, causing resource exhaustion and potential corruption of encrypted index data. Organizations using MongoDB should prioritize addressing this vulnerability to protect their data integrity and maintain service availability.
Original NVD Description
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.