Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-22083

Опубликовано: 17 дек. 2020
Источник: redhat
CVSS3: 0
EPSS Низкий

Описание

jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data

Python-jsonpickle allows remote code execution during deserialization of a malicious payload through the decode() function.

Отчет

Both jsonpickle and pickle are documented as being able to execute arbitrary code when loading pickles, and intended for use only with trusted data. This is expected behaviour, as clearly indicated in the jsonpickle README and at https://docs.python.org/3/library/pickle.html

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Tower 3python-jsonpickleNot affected
Red Hat Quay 3python-jsonpickleNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=1908869python-jsonpickle: deserialization of a malicious payload in the decode function can lead to RCE

EPSS

Процентиль: 89%
0.04696
Низкий

0 Low

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 5 лет назад

jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data

CVSS3: 9.8
nvd
около 5 лет назад

jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documented behaviour. pickle is known to be capable of causing arbitrary code execution, and must not be used with un-trusted data

CVSS3: 9.8
debian
около 5 лет назад

jsonpickle through 1.4.1 allows remote code execution during deseriali ...

CVSS3: 9.8
github
больше 3 лет назад

jsonpickle unsafe deserialization

EPSS

Процентиль: 89%
0.04696
Низкий

0 Low

CVSS3