Lucene search

K
cve[email protected]CVE-2024-5629
HistoryJun 05, 2024 - 3:15 p.m.

CVE-2024-5629

2024-06-0515:15:12
CWE-125
web.nvd.nist.gov
29
cve-2024-5629
pymongo
out-of-bounds read
bson module
deserialization
nvd

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%

An out-of-bounds read in the ‘bson’ module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.

Affected configurations

NVD
Node
mongodbpymongoRange<4.6.3
Node
debiandebian_linuxMatch10.0
CPENameOperatorVersion
mongodb:pymongomongodb pymongolt4.6.3

CNA Affected

[
  {
    "cpes": [
      "cpe:2.3:a:mongodb:python_driver:0.4:pre:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.5:pre:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.5.1:pre:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.5.2:pre:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.5.3:pre:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.6:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.7:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.7.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.7.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.8:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.8.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.9:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.9.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.9.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.9.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.9.4:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.9.5:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.10.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.10.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.10.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.11:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.11.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.11.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.11.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.12:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.13:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.14:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.14.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.14.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.15:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.15.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.15.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:0.16:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.1.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.1.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.2.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.4:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.5:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.5.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.5.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.6:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.7:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.8:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.8.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.9:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.10.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:1.11:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.0.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.1.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.2:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.2:rc1:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.2.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.3:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.3:rc1:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.4:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.4.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.4.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.5:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.5.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.5.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.6:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.6.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.6.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.6.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.7:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.7:rc0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.7:rc1:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.7.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.7.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.8:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.8:rc0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.8:rc1:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.8:rc2:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.8.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.9:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.9:rc0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.9.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.9.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.9.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.9.4:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:2.9.5:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3:b0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3:b1:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3:rc0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3:rc1:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.0.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.0.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.0.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.1:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.1:rc0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.1.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.2:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.2:rc0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.2.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.2.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.3.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.3.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.4:rc0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.4.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.5.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.5.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.6:rc0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.6.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.6.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.7.0:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.7.0:b0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.7.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.7.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.8.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.9.0:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.9.0:b0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.9.0:b1:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.10.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.10.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.11.0:-:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.11.0:b0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.11.0:b1:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.11.0:rc0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.11.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.11.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.11.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.11.4:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.12.0:b0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.12.0:b1:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.12.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.12.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.12.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:3.13.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.0.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.0.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.0.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.1.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.1.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.2.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.3.2:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.3.3:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.4.0:b0:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.4.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.4.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.5.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.6.0:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.6.1:*:*:*:*:mongodb:*:*",
      "cpe:2.3:a:mongodb:python_driver:4.6.2:*:*:*:*:mongodb:*:*"
    ],
    "defaultStatus": "unaffected",
    "product": "PyMongo",
    "vendor": "MongoDB Inc",
    "versions": [
      {
        "lessThanOrEqual": "4.6.2",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

4.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

37.3%