CVE-2021-47952
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
Debilidad
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute arbitrary code.
Referencias
- https://github.com/jsonpickle/jsonpickle
- https://jsonpickle.github.io
- https://www.exploit-db.com/exploits/49585
- https://www.vulncheck.com/advisories/python-jsonpickle-remote-code-execution-via-py-repr
- https://access.redhat.com/security/cve/CVE-2021-47952
- https://bugzilla.redhat.com/show_bug.cgi?id=2478170
Encuentra el fallo antes que un atacante.
Inicia sesión con GitHub y ejecuta tu primera auditoría en menos de un minuto. El plan gratuito no requiere tarjeta de crédito.