{
  "threat_severity" : "Low",
  "public_date" : "2024-06-05T00:00:00Z",
  "bugzilla" : {
    "description" : "python-pymongo: Out-of-bounds read in bson module",
    "id" : "2290585",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2290585"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.7",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-125",
  "details" : [ "An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.", "A flaw was found in the bson module contained in the python-pymongo package. A malformed BSON file may trigger an exception, leading to a denial of service and eventually sensitive memory data exposure." ],
  "statement" : "Only RHEL-8 is impacted by this vulnerability as `python-pymongo` is not packaged in RHEL-7 or RHEL-9.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2025-06-03T00:00:00Z",
    "advisory" : "RHSA-2025:8419",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "python36:3.6-8100020250430074622.4c5117ad"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "python27:2.7/python-pymongo",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.1",
    "fix_state" : "Fix deferred",
    "package_name" : "openstack-panko",
    "cpe" : "cpe:/a:redhat:openstack:16.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 16.2",
    "fix_state" : "Fix deferred",
    "package_name" : "openstack-panko",
    "cpe" : "cpe:/a:redhat:openstack:16.2"
  }, {
    "product_name" : "Red Hat OpenStack Platform 17.1",
    "fix_state" : "Fix deferred",
    "package_name" : "python-pymongo",
    "cpe" : "cpe:/a:redhat:openstack:17.1"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Not affected",
    "package_name" : "python-pymongo",
    "cpe" : "cpe:/a:redhat:satellite:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-5629\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-5629" ],
  "name" : "CVE-2024-5629",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}