Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mq5p-2mcr-m52j

Опубликовано: 30 авг. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Code injection in nbgitpuller

Impact

Due to an unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment.

Patches

0.10.2

Workarounds

None, other than upgrade to 0.10.2 or downgrade to 0.8.x.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

nbgitpuller

pip
Затронутые версииВерсия исправления

>= 0.9.0, <= 0.10.1

0.10.2

EPSS

Процентиль: 74%
0.00825
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-78
CWE-94

Связанные уязвимости

CVSS3: 9.6
nvd
больше 4 лет назад

nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. This has been resolved in version 0.10.2 and all users are advised to upgrade. No work around exist for users who can not upgrade.

EPSS

Процентиль: 74%
0.00825
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-78
CWE-94