Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9fq2-x9r6-wfmf

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Numpy Deserialization of Untrusted Data

** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.

Пакеты

Наименование

numpy

pip
Затронутые версииВерсия исправления

<= 1.16.0

Отсутствует

EPSS

Процентиль: 98%
0.57542
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.

CVSS3: 8.8
redhat
больше 6 лет назад

An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources

CVSS3: 9.8
nvd
больше 6 лет назад

An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources

CVSS3: 9.8
debian
больше 6 лет назад

An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickl ...

suse-cvrf
больше 5 лет назад

Security update for python-numpy

EPSS

Процентиль: 98%
0.57542
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-502