Описание
picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, allowing attackers to execute arbitrary code. Malicious pickle files embedding ensurepip._run_pip calls in reduce methods bypass picklescan detection and achieve remote code execution upon pickle.load() invocation.
EPSS
Процентиль: 47%
0.00638
Низкий
8.1 High
CVSS3
Дефекты
CWE-502
Связанные уязвимости
CVSS3: 8.1
github
12 месяцев назад
Picklescan is missing detection when calling built-in python ensurepip._run_pip
EPSS
Процентиль: 47%
0.00638
Низкий
8.1 High
CVSS3
Дефекты
CWE-502