bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pymongo | Jul 30, 2024 | Aug 15, 2013 |
| Mongodb | — | Upgrade MongoDB to version 2.5.1Upgrade to the latest version of MongoDB | Oct 31, 2019 | Aug 15, 2013 |
| Suse | — | Upgrade python-pymongoUpgrade python3-pymongo | Dec 12, 2013 | Aug 15, 2013 |
| Ubuntu | — | Upgrade python-bsonUpgrade python-bson-ext | Nov 8, 2024 | Aug 15, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub