Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gcr6-rf47-jrgf

Опубликовано: 13 июл. 2018
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Loaded Databook of Tablib prone to python insertion resulting in command execution

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

Пакеты

Наименование

tablib

pip
Затронутые версииВерсия исправления

< 0.11.5

0.11.5

EPSS

Процентиль: 91%
0.0487
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

CVSS3: 7.5
redhat
около 9 лет назад

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

CVSS3: 7.5
nvd
около 9 лет назад

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

CVSS3: 7.5
debian
около 9 лет назад

An exploitable vulnerability exists in the Databook loading functional ...

suse-cvrf
около 9 лет назад

Security update for python-tablib

EPSS

Процентиль: 91%
0.0487
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3