CyberRota Analysis
AI-GeneratedMongoid is vulnerable due to its failure to apply encryption rules for fields in embedded models when creating client-side field-level encryption schemas. This oversight allows sensitive data to be stored in plaintext, potentially exposing it to unauthorized users with read access to the database or backups. Organizations using Mongoid with enabled encryption features should prioritize addressing this vulnerability to protect sensitive information from unauthorized disclosure.
Original NVD Description
Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party with routine read access to the database, a backup, or the underlying data files may then see data that was meant to remain unreadable outside the application.
Related CVEs
Other vulnerabilities affecting the same vendor(s)