Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-5629

Опубликовано: 05 июн. 2024
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.

A flaw was found in the bson module contained in the python-pymongo package. A malformed BSON file may trigger an exception, leading to a denial of service and eventually sensitive memory data exposure.

Отчет

Only RHEL-8 is impacted by this vulnerability as python-pymongo is not packaged in RHEL-7 or RHEL-9.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8python27:2.7/python-pymongoFix deferred
Red Hat OpenStack Platform 16.1openstack-pankoFix deferred
Red Hat OpenStack Platform 16.2openstack-pankoFix deferred
Red Hat OpenStack Platform 17.1python-pymongoAffected
Red Hat Satellite 6python-pymongoNot affected
Red Hat Enterprise Linux 8python36FixedRHSA-2025:841903.06.2025

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2290585python-pymongo: Out-of-bounds read in bson module

EPSS

Процентиль: 47%
0.00238
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 1 года назад

An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.

CVSS3: 4.7
nvd
около 1 года назад

An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.

CVSS3: 4.7
debian
около 1 года назад

An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier ...

CVSS3: 4.7
redos
около 1 года назад

Уязвимость python3-pymongo

CVSS3: 4.7
github
около 1 года назад

PyMongo Out-of-bounds Read in the bson module

EPSS

Процентиль: 47%
0.00238
Низкий

4.7 Medium

CVSS3