Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g345-7jg6-m22p

Опубликовано: 23 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.1

Описание

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

EPSS

Процентиль: 4%
0.00139
Низкий

4.1 Medium

CVSS4

Дефекты

CWE-74

Связанные уязвимости

ubuntu
около 2 месяцев назад

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

CVSS3: 5.5
redhat
около 2 месяцев назад

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

nvd
около 2 месяцев назад

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

msrc
около 1 месяца назад

Configuration Injection via Carriage Return (\r) in write() method

debian
около 2 месяцев назад

When using the "configparser" module to write configuration files cont ...

EPSS

Процентиль: 4%
0.00139
Низкий

4.1 Medium

CVSS4

Дефекты

CWE-74