Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x33v-f3gp-gw2c

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Use of NullPointerException Catch to Detect NULL Pointer Dereference in Pymongo

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."

Пакеты

Наименование

pymongo

pip
Затронутые версииВерсия исправления

< 2.5.2

2.5.2

EPSS

Процентиль: 84%
0.02215
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-395

Связанные уязвимости

ubuntu
больше 12 лет назад

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."

redhat
больше 12 лет назад

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."

nvd
больше 12 лет назад

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."

debian
больше 12 лет назад

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2 ...

EPSS

Процентиль: 84%
0.02215
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-395