Описание
An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-lived cache to store the parsed JSON body. This cache is not thread-safe, meaning that incorrect JSON payloads could have been parsed for concurrent requests.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- Release NotesThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.1.3 (исключая)
cpe:2.3:a:webargs_project:webargs:*:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00363
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-362
Связанные уязвимости
EPSS
Процентиль: 58%
0.00363
Низкий
8.1 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-362