Опубликовано: 05 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8
Описание
ReviewBoard and Djblets library are vulnerable to code execution
An eval() vulnerability exists in Python Software Foundation Djblets version before 0.6.30 and 0.7.0 before 0.7.19 and Beanbag Review Board before 1.7.15 when parsing JSON requests allowing an attacker to execute arbitrary Python code.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-4409
- https://access.redhat.com/security/cve/cve-2013-4409
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4409
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88059
- https://github.com/djblets/djblets/blob/release-0.7.19/NEWS
- https://github.com/pypa/advisory-database/tree/main/vulns/djblets/PYSEC-2019-175.yaml
- https://security-tracker.debian.org/tracker/CVE-2013-4409
- https://web.archive.org/web/20200228151135/https://www.securityfocus.com/bid/63029
- https://www.reviewboard.org/docs/releasenotes/reviewboard/1.7.15
- http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120619.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-October/119819.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-October/119820.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-October/119830.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-October/119831.html
Пакеты
Наименование
djblets
pip
Затронутые версииВерсия исправления
< 0.6.30
0.6.30
Наименование
djblets
pip
Затронутые версииВерсия исправления
>= 0.7.0, < 0.7.19
0.7.19
Наименование
ReviewBoard
pip
Затронутые версииВерсия исправления
< 1.7.15
1.7.15
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 6 лет назад
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
CVSS3: 9.8
nvd
больше 6 лет назад
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
CVSS3: 9.8
debian
больше 6 лет назад
An eval() vulnerability exists in Python Software Foundation Djblets 0 ...