Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-50817

Опубликовано: 14 авг. 2025
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.

An unintended import flaw was found in the PyPI future package. When the module is loaded, it automatically imports test.py if present in the same directory or the sys.path. This behavior allows an attacker who can write files to the server to execute arbitrary code.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Serverlessopenshift-serverless-1/kn-eventing-istio-controller-rhel8Not affected
OpenShift Service Mesh 3openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/istio-cni-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/istio-must-gather-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/istio-pilot-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/istio-proxyv2-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/istio-rhel9-operatorNot affected
OpenShift Service Mesh 3openshift-service-mesh/istio-sail-operator-bundleNot affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/aap-cloud-metrics-collector-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-dev-tools-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2388642pypi-future: Python future unintended import

EPSS

Процентиль: 9%
0.00036
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
26 дней назад

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.

CVSS3: 5.4
nvd
26 дней назад

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.

CVSS3: 5.4
debian
26 дней назад

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary ...

suse-cvrf
7 дней назад

Security update for python-future

suse-cvrf
8 дней назад

Security update for python-future

EPSS

Процентиль: 9%
0.00036
Низкий

7.3 High

CVSS3