Description
An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
Published: 2024-06-05
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3832-1 pymongo security update
Debian DLA Debian DLA DLA-3889-1 pymongo security update
EUVD EUVD EUVD-2024-2101 An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.
Github GHSA Github GHSA GHSA-m87m-mmvp-v9qm PyMongo Out-of-bounds Read in the bson module
Ubuntu USN Ubuntu USN USN-6904-1 PyMongo vulnerability
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00238}

epss

{'score': 0.00069}


Fri, 06 Jun 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
Vendors & Products Redhat
Redhat enterprise Linux

Fri, 14 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Sep 2024 02:30:00 +0000

Type Values Removed Values Added
References

Subscriptions

Debian Debian Linux
Mongodb Pymongo Python Driver
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2025-02-13T17:54:22.106Z

Reserved: 2024-06-04T13:49:31.496Z

Link: CVE-2024-5629

cve-icon Vulnrichment

Updated: 2024-09-16T23:02:28.936Z

cve-icon NVD

Status : Modified

Published: 2024-06-05T15:15:12.737

Modified: 2024-11-21T09:48:02.860

Link: CVE-2024-5629

cve-icon Redhat

Severity : Low

Publid Date: 2024-06-05T00:00:00Z

Links: CVE-2024-5629 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses