Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-50817

Опубликовано: 14 авг. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 5.4

Описание

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.

РелизСтатусПримечание
devel

DNE

esm-apps/noble

needed

esm-apps/xenial

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

needs-triage

jammy

needed

noble

needed

plucky

DNE

upstream

needs-triage

Показывать по

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
redhat
26 дней назад

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.

CVSS3: 5.4
nvd
25 дней назад

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. When the module is loaded, it automatically imports test.py, if present in the same directory or in the sys.path. This behavior can be exploited by an attacker who has the ability to write files to the server, allowing the execution of arbitrary code.

CVSS3: 5.4
debian
25 дней назад

A vulnerability in the Python-Future 1.0.0 module allows for arbitrary ...

suse-cvrf
6 дней назад

Security update for python-future

suse-cvrf
8 дней назад

Security update for python-future

5.4 Medium

CVSS3