RSS   Vulnerabilities for 'Jw.util'   RSS

2020-05-22
 
CVE-2020-13388

CWE-78
 

 
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safe_load is not used.

 

 >>> Vendor: Python 28 Products
Python
Virtualenv
Beaker
Keyring
PIP
Setuptools
RPLY
Pyxdg
Pillow
Python-gnupg
Requests
Tgcaptcha2
Python priority library
Hpack
Hyper
Urllib3
Openpyxl
Tablib
Simplejson
Pykerberos
Pypiserver
RSA
Novajoin
Pyxml
Typed ast
Py-bcrypt
Jw.util
Pybluemonday


Copyright 2024, cxsecurity.com

 

Back to Top