Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27619

Опубликовано: 05 окт. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

In Python3's Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

Отчет

As of Red Hat Quay 3.4 the python runtime will be consumed from RHEL. Currently releases up to 3.3 won't get fixes for this moderate issue.

Меры по смягчению последствий

In versions of Python shipped with Red Hat Enterprise Linux and Red Hat Software Collections, the flaw can be mitigated by not running the python tests with network resources enabled. By default, the tests are not run with network resources enabled. Ensure that -u network or -uall are not passed as options to python -m test. For more information on how these commands work, see [1].

  1. https://docs.python.org/3/library/test.html

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pythonOut of support scope
Red Hat Enterprise Linux 6pythonOut of support scope
Red Hat Enterprise Linux 7pythonOut of support scope
Red Hat Enterprise Linux 7python3Out of support scope
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Quay 3quayWill not fix
Red Hat Software Collectionsrh-python36-pythonOut of support scope
Red Hat Enterprise Linux 8python3FixedRHSA-2021:163318.05.2021
Red Hat Enterprise Linux 8python27FixedRHSA-2021:415109.11.2021
Red Hat Enterprise Linux 8python38FixedRHSA-2021:416209.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-95
https://bugzilla.redhat.com/show_bug.cgi?id=1889886python: Unsafe use of eval() on data retrieved via HTTP in the test suite

EPSS

Процентиль: 73%
0.00785
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

CVSS3: 9.8
nvd
больше 4 лет назад

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

CVSS3: 9.8
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 9.8
debian
больше 4 лет назад

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK ...

suse-cvrf
около 4 лет назад

Security update for python3

EPSS

Процентиль: 73%
0.00785
Низкий

7.5 High

CVSS3