Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-17175

Опубликовано: 18 сент. 2018
Источник: ubuntu
Приоритет: low
CVSS2: 5
CVSS3: 5.3

Описание

In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only").

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

not-affected

3.0.0b14-1
disco

not-affected

3.0.0b14-1
eoan

not-affected

3.0.0b14-1
esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

3.0.0b14-1
esm-apps/jammy

not-affected

3.0.0b14-1
esm-apps/noble

not-affected

3.0.0b14-1
esm-infra-legacy/trusty

DNE

Показывать по

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 7 лет назад

In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only").

CVSS3: 5.3
debian
больше 7 лет назад

In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Py ...

CVSS3: 5.3
github
больше 7 лет назад

In marshmallow library the schema "only" option treats an empty list as implying no "only" option

5 Medium

CVSS2

5.3 Medium

CVSS3