Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9x4c-63pf-525f

Опубликовано: 20 авг. 2020
Источник: github
Github: Прошло ревью
CVSS4: 8.8
CVSS3: 8

Описание

openapi-python-client Arbitrary Code Generation vulnerability

Impact

Clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.

Giving this a CVSS of 8.0 (high) with CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H/E:P/RL:U/RC:C .

Patches

Fix will be included in version 0.5.3

Workarounds

Inspect OpenAPI documents before generating, or inspect generated code before executing.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

openapi-python-client

pip
Затронутые версииВерсия исправления

< 0.5.3

0.5.3

EPSS

Процентиль: 73%
0.00757
Низкий

8.8 High

CVSS4

8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8
nvd
больше 5 лет назад

In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.

EPSS

Процентиль: 73%
0.00757
Низкий

8.8 High

CVSS4

8 High

CVSS3

Дефекты

CWE-94