GHSA-5qw9-p5cj-5jx4HighCVSS 6.5
A protection mechanism failure in the object-document mapper's encryption configuration...
🔗 CVE IDs covered (1)
📋 Description
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.