CVE-2021-47952
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
Schwachstellenklasse
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
Quellen
- https://github.com/jsonpickle/jsonpickle
- https://jsonpickle.github.io
- https://www.exploit-db.com/exploits/49585
- https://www.vulncheck.com/advisories/python-jsonpickle-remote-code-execution-via-py-repr
- https://access.redhat.com/security/cve/CVE-2021-47952
- https://bugzilla.redhat.com/show_bug.cgi?id=2478170
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.