PT-2019-16623 · Pypi · Sqla Yaml Fixtures

Bigbigliang-Malwarebenchmark

·

Published

2019-01-03

·

Updated

2019-01-31

·

CVE-2019-3575

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sqla yaml fixtures versions up to 0.9.1
Description The issue allows local users to execute arbitrary python code via the fixture text argument in the sqla yaml fixtures.load function. This can lead to code execution with the privileges of the user running the application.
Recommendations For Sqla yaml fixtures versions up to 0.9.1, consider restricting access to the sqla yaml fixtures.load function to minimize the risk of exploitation. As a temporary workaround, avoid using the fixture text argument in the sqla yaml fixtures.load function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3575
GHSA-2X54-J4M3-R6WX
PYSEC-2019-122

Affected Products

Sqla Yaml Fixtures