Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2810

Опубликовано: 13 июн. 2017
Источник: redhat
CVSS3: 7.5

Описание

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

It was found that loading a yaml format Databook from an untrusted source could lead to arbitrary code execution in python-tablib as the safe_load method was not used to load the content.

Отчет

Red Hat Product Security has rated this issue as having Low security impact in Red Hat OpenStack Platform. While the code is present in the python-tablib package, it is not reachable in any supported configuration. There is currently no plan to address this flaw in any supported version of Red Hat OpenStack platform.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 10 (Newton)python-tablibWill not fix
Red Hat OpenStack Platform 11 (Ocata)python-tablibWill not fix
Red Hat OpenStack Platform 12 (Pike)python-tablibNot affected
Red Hat OpenStack Platform 8 (Liberty)python-tablibWill not fix
Red Hat OpenStack Platform 9 (Mitaka)python-tablibWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=1461297python-tablib: Databook loading functionality allows command execution

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

CVSS3: 7.5
nvd
больше 8 лет назад

An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker can insert python into loaded yaml to trigger this vulnerability.

CVSS3: 7.5
debian
больше 8 лет назад

An exploitable vulnerability exists in the Databook loading functional ...

suse-cvrf
больше 8 лет назад

Security update for python-tablib

suse-cvrf
больше 8 лет назад

Security update for python-tablib

7.5 High

CVSS3