Количество 4
Количество 4
CVE-2018-17175
In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only").
CVE-2018-17175
In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only").
CVE-2018-17175
In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Py ...
GHSA-9q2p-fj49-vpxj
In marshmallow library the schema "only" option treats an empty list as implying no "only" option
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-17175 In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only"). | CVSS3: 5.3 | 0% Низкий | больше 7 лет назад | |
CVE-2018-17175 In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the "only" option, and there is a user role that produces an empty value for "only"). | CVSS3: 5.3 | 0% Низкий | больше 7 лет назад | |
CVE-2018-17175 In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Py ... | CVSS3: 5.3 | 0% Низкий | больше 7 лет назад | |
GHSA-9q2p-fj49-vpxj In marshmallow library the schema "only" option treats an empty list as implying no "only" option | CVSS3: 5.3 | 0% Низкий | больше 7 лет назад |
Уязвимостей на страницу