Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gcr6-rf47-jrgf

Опубликовано: 13 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Loaded Databook of Tablib prone to python insertion resulting in command execution

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

Пакеты

Наименование

tablib

pip
Затронутые версииВерсия исправления

< 0.11.5

0.11.5

EPSS

Процентиль: 87%
0.0328
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

CVSS3: 7.5
redhat
больше 8 лет назад

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

CVSS3: 7.5
nvd
больше 8 лет назад

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

CVSS3: 7.5
debian
больше 8 лет назад

An exploitable vulnerability exists in the Databook loading functional ...

suse-cvrf
больше 8 лет назад

Security update for python-tablib

EPSS

Процентиль: 87%
0.0328
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3