Vulnerability Description
When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mongodb | C Driver | < 1.25.0 |
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/CDRIVER-4747Issue TrackingVendor Advisory
- https://lists.fedoraproject.org/archives/list/[email protected]
- https://jira.mongodb.org/browse/CDRIVER-4747Issue TrackingVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/05/msg00012.html
- https://lists.debian.org/debian-lts-announce/2025/05/msg00027.html
- https://lists.fedoraproject.org/archives/list/[email protected]
FAQ
What is CVE-2023-0437?
CVE-2023-0437 is a vulnerability with a CVSS score of 5.3 (MEDIUM). When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions...
How severe is CVE-2023-0437?
CVE-2023-0437 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0437?
Check the references section above for vendor advisories and patch information. Affected products include: Mongodb C Driver.