CVE-2024-5629
published 2024-06-05CVE-2024-5629: An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception…
PriorityP340high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
0.66%
48.2th percentile
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | pymongo | < pymongo 3.11.0-1+deb12u1 (bookworm) | pymongo 3.11.0-1+deb12u1 (bookworm) |
| mongodb | pymongo | < 4.6.3 | 4.6.3 |
| mongodb_inc | pymongo | <= 4.6.2 | — |
| mongodb_inc | pymongo | >= 0 < 3.11.0-1+deb11u1 | 3.11.0-1+deb11u1 |
| mongodb_inc | pymongo | >= 0 < 3.11.0-1+deb12u1 | 3.11.0-1+deb12u1 |
| mongodb_inc | pymongo | >= 0 < 4.7.3-1 | 4.7.3-1 |
| mongodb_inc | pymongo | >= 0 < 4.7.3-1 | 4.7.3-1 |
| mongodb_inc | pymongo | >= 0 < 4.6.3 | 4.6.3 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
ghsa8.1HIGH
osv8.1HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PyMongo vulnerability
vendor_ubuntu·2024-07-22
CVE-2024-5629 PyMongo vulnerability
Title: PyMongo vulnerability
Summary: PyMongo could be made to crash or expose sensitive information if it
received a crafted BSON.
It was discovered that PyMongo incorrectly handled certain BSON.
An attacker could possibly use this issue to read sensitive information
or cause a crash.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-pymongo: Out-of-bounds read in bson module
vendor_redhat·2024-06-05·CVSS 4.7
CVE-2024-5629 [MEDIUM] CWE-125 python-pymongo: Out-of-bounds read in bson module
python-pymongo: Out-of-bounds read in bson module
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
A flaw was found in the bson module contained in the python-pymongo package. A malformed BSON file may trigger an exception, leading to a denial of service and eventually sensitive memory data exposure.
Statement: Only RHEL-8 is impacted by this vulnerability as `python-pymongo` is not packaged in RHEL-7 or RHEL-9.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation
Debian
CVE-2024-5629: pymongo - An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows de...
vendor_debian·2024·CVSS 4.7
CVE-2024-5629 [MEDIUM] CVE-2024-5629: pymongo - An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows de...
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
Scope: local
bookworm: resolved (fixed in 3.11.0-1+deb12u1)
bullseye: resolved (fixed in 3.11.0-1+deb11u1)
forky: resolved (fixed in 4.7.3-1)
sid: resolved (fixed in 4.7.3-1)
trixie: resolved (fixed in 4.7.3-1)
OSV
PyMongo Out-of-bounds Read in the bson module
osv·2024-06-05
CVE-2024-5629 [MEDIUM] PyMongo Out-of-bounds Read in the bson module
PyMongo Out-of-bounds Read in the bson module
Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.
OSV
CVE-2024-5629: An out-of-bounds read in the 'bson' module of PyMongo 4
osv·2024-06-05·CVSS 8.1
CVE-2024-5629 [HIGH] CVE-2024-5629: An out-of-bounds read in the 'bson' module of PyMongo 4
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
GHSA
PyMongo Out-of-bounds Read in the bson module
ghsa·2024-06-05
CVE-2024-5629 [MEDIUM] CWE-125 PyMongo Out-of-bounds Read in the bson module
PyMongo Out-of-bounds Read in the bson module
Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.
OSV
PyMongo Out-of-bounds Read in the bson module
osv·2024-04-06·CVSS 8.1
CVE-2024-21506 [HIGH] PyMongo Out-of-bounds Read in the bson module
PyMongo Out-of-bounds Read in the bson module
Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.
This advisory was initially published as CVE-2024-21506, which has since been rejected as a duplicate of CVE-2024-5629.
GHSA
PyMongo Out-of-bounds Read in the bson module
ghsa·2024-04-06·CVSS 8.1
CVE-2024-21506 [HIGH] CWE-125 PyMongo Out-of-bounds Read in the bson module
PyMongo Out-of-bounds Read in the bson module
Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.
This advisory was initially published as CVE-2024-21506, which has since been rejected as a duplicate of CVE-2024-5629.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-05
Published