Описание
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| python-click | fixed | 8.3.3-1~exp1 | experimental | package |
| python-click | fixed | 8.3.3-1 | package | |
| python-click | no-dsa | trixie | package | |
| python-click | no-dsa | bookworm | package | |
| python-click | postponed | bullseye | package |
Примечания
https://github.com/tsigouris007/security-advisories/security/advisories/GHSA-47fr-3ffg-hgmw
Fixed by: https://github.com/pallets/click/commit/b96c2601af4e01341b4d2c0db494ebee4aef8f42 (8.3.3)
EPSS
Связанные уязвимости
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
Pallets Click contains a command injection via Unsanitized Filename "click.edit()"
EPSS