Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-27607

Опубликовано: 07 мар. 2025
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0.

A flaw was found in the Python JSON Logger library (python-json-logger). In affected versions, python-json-logger was vulnerable to remote code execution (RCE) due to a missing dependency. This issue occurred because msgspec-python313-pre was deleted by the owner, leaving the name open to being claimed by a third party. If the package were claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13, such as pip install python-json-logger[dev].

Отчет

None of the Red Hat Products and Services are impacted by this vulnerability.

Меры по смягчению последствий

No mitigation is available for this issue other than updating the affected package to the version containing the fix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2python-json-loggerNot affected
Red Hat OpenStack Platform 17.1python-json-loggerNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-829
https://bugzilla.redhat.com/show_bug.cgi?id=2350638python-json-logger: Python JSON Logger has a Potential RCE via missing `msgspec-python313-pre` dependency

EPSS

Процентиль: 87%
0.03662
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
6 месяцев назад

Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0.

CVSS3: 8.8
nvd
6 месяцев назад

Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to RCE through a missing dependency. This occurred because msgspec-python313-pre was deleted by the owner leaving the name open to being claimed by a third party. If the package was claimed, it would allow them RCE on any Python JSON Logger user who installed the development dependencies on Python 3.13 (e.g. pip install python-json-logger[dev]). This issue has been resolved with 3.3.0.

CVSS3: 8.8
debian
6 месяцев назад

Python JSON Logger is a JSON Formatter for Python Logging. Between 30 ...

CVSS3: 8.8
fstec
9 месяцев назад

Уязвимость библиотеки Python JSON Logger языка программирования Python, связанная с включением функций из недостоверной контролируемой области, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 87%
0.03662
Низкий

8.8 High

CVSS3