Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9q2p-fj49-vpxj

Опубликовано: 10 окт. 2018
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

In marshmallow library the schema "only" option treats an empty list as implying no "only" option

In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only").

Пакеты

Наименование

marshmallow

pip
Затронутые версииВерсия исправления

< 2.15.1

2.15.1

Наименование

marshmallow

pip
Затронутые версииВерсия исправления

>= 3.0a0, < 3.0.0b9

3.0.0b9

EPSS

Процентиль: 41%
0.00189
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-358

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only").

CVSS3: 5.3
nvd
больше 7 лет назад

In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only").

CVSS3: 5.3
debian
больше 7 лет назад

In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Py ...

EPSS

Процентиль: 41%
0.00189
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-358