Опубликовано: 26 дек. 2018
Источник: github
Github: Прошло ревью
CVSS4: 8.1
CVSS3: 9.8
Описание
Code injection in Danijar Definitions
There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.
Пакеты
Наименование
definitions
pip
Затронутые версииВерсия исправления
<= 0.2.0
Отсутствует
Связанные уязвимости
CVSS3: 9.8
nvd
около 7 лет назад
There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.