Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-58367

Опубликовано: 05 сент. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnerable to class pollution via the Delta class constructor, and when combined with a gadget available in DeltaDiff, it can lead to Denial of Service and Remote Code Execution (via insecure Pickle deserialization) exploitation. The gadget available in DeepDiff allows deepdiff.serialization.SAFE_TO_IMPORT to be modified to allow dangerous classes such as posix.system, and then perform insecure Pickle deserialization via the Delta class. This potentially allows any Python code to be executed, given that the input to Delta is user-controlled. Depending on the application where DeepDiff is used, this can also lead to other vulnerabilities. This is fixed in version 8.6.1.

РелизСтатусПримечание
devel

not-affected

8.6.1-1
esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

not-affected

8.6.1-1
jammy

needs-triage

noble

needs-triage

questing

ignored

end of life, was needs-triage
resolute

not-affected

8.6.1-1
upstream

released

8.6.1-1

Показывать по

EPSS

Процентиль: 64%
0.01123
Низкий

Связанные уязвимости

nvd
12 месяцев назад

DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnerable to class pollution via the Delta class constructor, and when combined with a gadget available in DeltaDiff, it can lead to Denial of Service and Remote Code Execution (via insecure Pickle deserialization) exploitation. The gadget available in DeepDiff allows `deepdiff.serialization.SAFE_TO_IMPORT` to be modified to allow dangerous classes such as posix.system, and then perform insecure Pickle deserialization via the Delta class. This potentially allows any Python code to be executed, given that the input to Delta is user-controlled. Depending on the application where DeepDiff is used, this can also lead to other vulnerabilities. This is fixed in version 8.6.1.

debian
12 месяцев назад

DeepDiff is a project focused on Deep Difference and search of any Pyt ...

suse-cvrf
12 месяцев назад

Security update for python-deepdiff

github
около 1 года назад

DeepDiff Class Pollution in Delta class leading to DoS, Remote Code Execution, and more

EPSS

Процентиль: 64%
0.01123
Низкий