Описание
A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handler. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used.
Ссылки
- ExploitIssue Tracking
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue Tracking
Уязвимые конфигурации
Конфигурация 1Версия до 0.55.6 (включая)
cpe:2.3:a:upsonic:upsonic:*:*:*:*:*:*:*:*
EPSS
Процентиль: 17%
0.00055
Низкий
5.5 Medium
CVSS3
8 High
CVSS3
5.2 Medium
CVSS2
Дефекты
CWE-20
CWE-502
Связанные уязвимости
CVSS3: 5.5
github
8 месяцев назад
Upsonic has vulnerability in Pickle Handler component that can lead to deserialization
EPSS
Процентиль: 17%
0.00055
Низкий
5.5 Medium
CVSS3
8 High
CVSS3
5.2 Medium
CVSS2
Дефекты
CWE-20
CWE-502