MongoDB

Mongoid

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 18.09.2026 17:27:51
  • Zuletzt bearbeitet 24.09.2026 16:19:37

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a ...

  • EPSS 0.28%
  • Veröffentlicht 18.09.2026 17:24:03
  • Zuletzt bearbeitet 24.09.2026 16:07:38

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party wi...

  • EPSS 0.27%
  • Veröffentlicht 18.09.2026 17:20:34
  • Zuletzt bearbeitet 24.09.2026 16:06:04

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place us...

  • EPSS 0.34%
  • Veröffentlicht 18.09.2026 17:15:17
  • Zuletzt bearbeitet 24.09.2026 16:05:13

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disc...

  • EPSS 0.1%
  • Veröffentlicht 18.09.2026 17:10:24
  • Zuletzt bearbeitet 24.09.2026 16:00:39

A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning....

  • EPSS 0.1%
  • Veröffentlicht 18.09.2026 17:06:27
  • Zuletzt bearbeitet 24.09.2026 16:00:04

Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with n...

  • EPSS 0.29%
  • Veröffentlicht 18.09.2026 17:01:09
  • Zuletzt bearbeitet 25.09.2026 14:10:39

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method i...

  • EPSS 0.21%
  • Veröffentlicht 18.09.2026 16:56:41
  • Zuletzt bearbeitet 25.09.2026 14:12:35

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause...