Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ch3j-w953-hfcm

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 10
CVSS3: 9

Описание

graphite-web is vulnerable to Remote Code Execution

Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to (1) remote_storage.py, (2) storage.py, (3) render/datalib.py, and (4) whitelist/views.py, a different vulnerability than CVE-2013-5093.

Пакеты

Наименование

graphite-web

pip
Затронутые версииВерсия исправления

>= 0.9.5, <= 0.9.10

0.9.11

EPSS

Процентиль: 81%
0.01535
Низкий

10 Critical

CVSS4

9 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 12 лет назад

Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to (1) remote_storage.py, (2) storage.py, (3) render/datalib.py, and (4) whitelist/views.py, a different vulnerability than CVE-2013-5093.

nvd
больше 12 лет назад

Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to (1) remote_storage.py, (2) storage.py, (3) render/datalib.py, and (4) whitelist/views.py, a different vulnerability than CVE-2013-5093.

debian
больше 12 лет назад

Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, ...

EPSS

Процентиль: 81%
0.01535
Низкий

10 Critical

CVSS4

9 Critical

CVSS3

Дефекты

CWE-94