Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8554-jxcw-454q

Опубликовано: 12 мар. 2019
Источник: github
Github: Прошло ревью
CVSS4: 8.2
CVSS3: 8.1

Описание

Webargs mishandles concurrent JSON parsing

An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-lived cache to store the parsed JSON body. This cache is not thread-safe, meaning that incorrect JSON payloads could have been parsed for concurrent requests.

Пакеты

Наименование

webargs

pip
Затронутые версииВерсия исправления

< 5.1.3

5.1.3

EPSS

Процентиль: 58%
0.00363
Низкий

8.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.1
nvd
почти 7 лет назад

An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-lived cache to store the parsed JSON body. This cache is not thread-safe, meaning that incorrect JSON payloads could have been parsed for concurrent requests.

EPSS

Процентиль: 58%
0.00363
Низкий

8.2 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-362