Описание
cryptidy allows code execution via untrusted data due to pickle.loads
cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.
Пакеты
Наименование
cryptidy
pip
Затронутые версииВерсия исправления
<= 1.2.4
Отсутствует
Связанные уязвимости
CVSS3: 6.9
nvd
3 месяца назад
cryptidy through 1.2.4 allows code execution via untrusted data because pickle.loads is used. This occurs in aes_decrypt_message in symmetric_encryption.py.