Описание
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Ссылки
- ExploitVendor Advisory
Уязвимые конфигурации
EPSS
10 Critical
CVSS3
Дефекты
Связанные уязвимости
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 an ...
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
EPSS
10 Critical
CVSS3