Описание
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute system commands and arbitrary code.
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute system commands and arbitrary code.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-47952
- https://access.redhat.com/security/cve/CVE-2021-47952
- https://bugzilla.redhat.com/show_bug.cgi?id=2478170
- https://github.com/jsonpickle/jsonpickle
- https://jsonpickle.github.io
- https://security.access.redhat.com/data/csaf/v2/vex/2021/cve-2021-47952.json
- https://www.exploit-db.com/exploits/49585
- https://www.vulncheck.com/advisories/python-jsonpickle-remote-code-execution-via-py-repr
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
Связанные уязвимости
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
python jsonpickle 2.0.0 contains a remote code execution vulnerability ...
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3