CyberRota Analysis
AI-GeneratedMongoDB's libmongocrypt is vulnerable due to a missing input validation in its automatic-encryption context setup, allowing unsanitized caller-supplied database identifiers. This flaw can result in incorrect schema selection, potentially leading to limited information disclosure or unauthorized modifications. Organizations using MongoDB should prioritize addressing this vulnerability to mitigate risks associated with data integrity and confidentiality.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited to incorrect schema selection, which may lead to limited disclosure or modification of information handled by the application.
Related CVEs
Other vulnerabilities affecting the same vendor(s)