Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cvp7-c586-cmf4

Опубликовано: 28 янв. 2022
Источник: github
Github: Прошло ревью

Описание

Withdrawn: Code Injection in loguru

Withdrawn

This advisory has been withdrawn after the maintainers of loguru noted this issue is not a security vulnerability and the CVE has been revoked. We have stopped Dependabot alerts regarding this issue.

Original Description

In versions of loguru up to and including 0.5.3 a lack of sanitization on log serialization can lead to arbitrary code execution. The maintainer disputes the issue, but has altered behavior of the library in commit 4b0070a4f30cbf6d5e12e6274b242b62ea11c81b. See https://github.com/Delgan/loguru/issues/563 for further discussion of the issue. The function in question is intended for internal use only, but is not restricted. This has been patched in version 0.6.0.

Пакеты

Наименование

loguru

pip
Затронутые версииВерсия исправления

<= 0.5.3

0.6.0

Дефекты

CWE-94

Связанные уязвимости

ubuntu
около 4 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

nvd
около 4 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage

Дефекты

CWE-94