• CVE-2024-5629

发布时间: 2024年6月6日

修改时间: 2024年7月2日

概要

An out-of-bounds read in the bson module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.

CVSS v3 指标

NVD openEuler
Confidentiality High Low
Attack Vector Network Network
CVSS评分 8.1 4.7
Attack Complexity Low High
Privileges Required None None
Scope Unchanged Changed
Integrity None None
User Interaction Required Required
Availability High Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-2641 An out-of-bounds read in the bson module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory. 2024年6月6日

影响产品

产品 状态
KY3.4-5A python-pymongo Unaffected
KY3.5.2 python-pymongo Unaffected
V6 python-pymongo Unaffected