PT-2020-14222 · Openai · Openapi-Python-Client
Dbanty
+2
·
Published
2020-08-14
·
Updated
2020-08-20
·
CVE-2020-15142
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openapi-python-client versions prior to 0.5.3
Description
The issue allows clients generated with a maliciously crafted OpenAPI Document to generate arbitrary Python code, leading to arbitrary code execution when the malicious client is executed.
Recommendations
For versions prior to 0.5.3, update to version 0.5.3 to resolve the issue.
As a temporary workaround, consider inspecting OpenAPI documents before generating clients or inspecting generated code before executing it to minimize the risk of exploitation.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openapi-Python-Client