Safety vulnerability ID: 33131
The information on this page was manually curated by our Cybersecurity Intelligence Team.
The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent use of the os module, which allows local users to bypass intended access restrictions and execute arbitrary commands via a file_blob_storage.os reference within the code parameter to _ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.
Latest version: 1.5.1
Google AppEngine (unofficial easy-installable version of AppEngine SDK)
The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent use of the os module, which allows local users to bypass intended access restrictions and execute arbitrary commands via a file_blob_storage.os reference within the code parameter to _ah/admin/interactive/execute, a different vulnerability than CVE-2011-1364.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application